design-web
Fail
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: CRITICALEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: A URL referenced in the premium patterns documentation (
mivora-wbs.framer.website) has been flagged by automated security scanners as a confirmed phishing site. This domain is used as a source for design techniques within the skill. - [REMOTE_CODE_EXECUTION]: The design reference for the
cursor-recodemockup contains the high-risk command patterncurl https://cursor.com/install -fsS | bash. While this is presented as part of a UI demonstration, the inclusion of piped remote script execution patterns is a significant security risk if processed or accidentally executed by an AI agent. - [INDIRECT_PROMPT_INJECTION]: The skill uses browser tools to ingest content from arbitrary external production websites to inform design decisions.
- Ingestion points: Files
references/design-inspiration.mdandreferences/design-inspiration-urls.mdinstruct the agent to usemcp__fuse-browser__*to navigate to and capture content from external URLs. - Boundary markers: Absent. The skill does not provide explicit delimiters or warnings to the model to ignore instructions found within the browsed websites.
- Capability inventory: The agent has the capability to write and edit files on the local filesystem and invoke external generation APIs via the Gemini Design MCP.
- Sanitization: Absent. There are no mechanisms described to filter or sanitize text extracted from external sites before it is used in subsequent prompting phases.
Recommendations
- AI detected serious security threats
- Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata