experience-design-validate
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructions direct the agent to analyze untrusted visual evidence supplied by users or fetched from live URLs and Figma. This creates a vulnerability surface where malicious text or instructions embedded within the screenshots or websites could attempt to influence the agent's audit results or behavior. * Ingestion points: Visual artifacts including screenshots, live URLs, Figma frames, and screen recordings (SKILL.md). * Boundary markers: The instructions do not define delimiters or explicit 'ignore' rules for text detected within the analyzed visual artifacts. * Capability inventory: The skill is limited to visual analysis and report generation; it does not define shell commands, subprocess execution, or sensitive file access. * Sanitization: The skill contains no directives for filtering or sanitizing text extracted from the visual evidence before it is processed by the agent's reasoning model.
Audit Metadata