web-release-gate
Pass
Audited by Gen Agent Trust Hub on Aug 20, 2026
Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest and prioritize information from several local repository files, which creates a surface for indirect prompt injection if those files contain malicious instructions.\n
- Ingestion points:
SKILL.mddirects the agent to readdesign.md,taste.md,tailwind.config.js,lib/design-system.*,CLAUDE.md, andAGENTS.md.\n - Boundary markers: Absent. The instructions do not define delimiters or specific warnings to ignore embedded instructions within these data sources.\n
- Capability inventory: The skill coordinates tools that perform file writing (
image-to-code), environment interaction (visual-proof), and external data retrieval (web-design-guidelines).\n - Sanitization: Absent. There are no instructions to sanitize or validate the content of the ingested files before processing.\n- [DATA_EXPOSURE_AND_EXFILTRATION]: The skill documentation indicates that one of the audit tools performs network requests to retrieve updated guidelines.\n
- Evidence: The
web-design-guidelinesspecialist skill is described as fetching "live Web Interface Guidelines" during the audit phase.
Audit Metadata