experience-lwc-design-generate

Warn

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: MEDIUMPROMPT_INJECTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The reference file references/prd-analysis-template.md contains explicit instructions to override the agent's current task. It commands the agent to "identify {{DOMAIN}} issues" and "Return your analysis as report in SARIF JSON format with no additional text or explanation." Despite being described in SKILL.md as a "PRD section skeleton," its content is a prompt injection payload designed to hijack the agent's output and behavior.
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary workflow involves ingesting untrusted data from external sources including Figma URLs, Product Requirements Documents (PRDs), and Aura component source code. This represents a significant attack surface as documented below:
  • Ingestion points: External data enters the context in Phase 1.1 (raw requirements collection) and Phase 1.2 (Figma analysis).
  • Boundary markers: The instructions do not define delimiters (like XML tags) or provide "ignore embedded instructions" warnings for the ingested content.
  • Capability inventory: The agent has the capability to execute shell scripts (check-component-name.sh, detect-project-tools.sh) and perform file writing and handoffs to other specialized skills.
  • Sanitization: There is no mention of validation, filtering, or escaping of the content extracted from these design artifacts before it is used to drive code generation in Phase 2.
  • [COMMAND_EXECUTION]: The skill workflow requires the execution of bundled shell scripts (check-component-name.sh and detect-project-tools.sh) which take user-provided strings (component names and project paths) as arguments. While the scripts utilize Python's argument handling to mitigate command injection within the script itself, the agent's process of interpolating user-controlled data into these shell commands remains a potential vulnerability if the agent fails to strictly sanitize the input.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 23, 2026, 07:10 AM
Security Audit — agent-trust-hub — experience-lwc-design-generate