experience-lwc-design-generate
Warn
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: MEDIUMPROMPT_INJECTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The reference file
references/prd-analysis-template.mdcontains explicit instructions to override the agent's current task. It commands the agent to "identify {{DOMAIN}} issues" and "Return your analysis as report in SARIF JSON format with no additional text or explanation." Despite being described inSKILL.mdas a "PRD section skeleton," its content is a prompt injection payload designed to hijack the agent's output and behavior. - [INDIRECT_PROMPT_INJECTION]: The skill's primary workflow involves ingesting untrusted data from external sources including Figma URLs, Product Requirements Documents (PRDs), and Aura component source code. This represents a significant attack surface as documented below:
- Ingestion points: External data enters the context in Phase 1.1 (raw requirements collection) and Phase 1.2 (Figma analysis).
- Boundary markers: The instructions do not define delimiters (like XML tags) or provide "ignore embedded instructions" warnings for the ingested content.
- Capability inventory: The agent has the capability to execute shell scripts (
check-component-name.sh,detect-project-tools.sh) and perform file writing and handoffs to other specialized skills. - Sanitization: There is no mention of validation, filtering, or escaping of the content extracted from these design artifacts before it is used to drive code generation in Phase 2.
- [COMMAND_EXECUTION]: The skill workflow requires the execution of bundled shell scripts (
check-component-name.shanddetect-project-tools.sh) which take user-provided strings (component names and project paths) as arguments. While the scripts utilize Python's argument handling to mitigate command injection within the script itself, the agent's process of interpolating user-controlled data into these shell commands remains a potential vulnerability if the agent fails to strictly sanitize the input.
Audit Metadata