web-release-gate

Pass

Audited by Gen Agent Trust Hub on Aug 20, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest and prioritize information from several local repository files, which creates a surface for indirect prompt injection if those files contain malicious instructions.\n
  • Ingestion points: SKILL.md directs the agent to read design.md, taste.md, tailwind.config.js, lib/design-system.*, CLAUDE.md, and AGENTS.md.\n
  • Boundary markers: Absent. The instructions do not define delimiters or specific warnings to ignore embedded instructions within these data sources.\n
  • Capability inventory: The skill coordinates tools that perform file writing (image-to-code), environment interaction (visual-proof), and external data retrieval (web-design-guidelines).\n
  • Sanitization: Absent. There are no instructions to sanitize or validate the content of the ingested files before processing.\n- [DATA_EXPOSURE_AND_EXFILTRATION]: The skill documentation indicates that one of the audit tools performs network requests to retrieve updated guidelines.\n
  • Evidence: The web-design-guidelines specialist skill is described as fetching "live Web Interface Guidelines" during the audit phase.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 20, 2026, 11:06 AM
Security Audit — agent-trust-hub — web-release-gate