app-icon-design
Pass
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to use
ripgrep(rg) to discover available style modules within the skill'sreferencesdirectory. This is a local discovery mechanism used for internal navigation of provided assets. - [PROMPT_INJECTION]: The skill is designed to process untrusted context such as user briefs, screenshots, and repository metadata, which creates an attack surface for indirect prompt injection.
- Ingestion points:
SKILL.md(briefs, repository metadata, screenshots, existing icons, brand assets). - Boundary markers: Absent.
- Capability inventory:
SKILL.md(local command execution, image generation, file-writing for exports). - Sanitization: Absent.
- [SAFE]: The skill references official documentation and guidelines from trusted organizations including Apple, Google, Microsoft, and Mozilla to ensure design compliance across different operating systems.
Audit Metadata