skills/fine405/skills/app-icon-design/Gen Agent Trust Hub

app-icon-design

Pass

Audited by Gen Agent Trust Hub on Aug 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to use ripgrep (rg) to discover available style modules within the skill's references directory. This is a local discovery mechanism used for internal navigation of provided assets.
  • [PROMPT_INJECTION]: The skill is designed to process untrusted context such as user briefs, screenshots, and repository metadata, which creates an attack surface for indirect prompt injection.
  • Ingestion points: SKILL.md (briefs, repository metadata, screenshots, existing icons, brand assets).
  • Boundary markers: Absent.
  • Capability inventory: SKILL.md (local command execution, image generation, file-writing for exports).
  • Sanitization: Absent.
  • [SAFE]: The skill references official documentation and guidelines from trusted organizations including Apple, Google, Microsoft, and Mozilla to ensure design compliance across different operating systems.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 18, 2026, 03:18 AM
Security Audit — agent-trust-hub — app-icon-design