design-review
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill offers a one-time setup to download the 'impeccable' design detector engine from a public GitHub repository. While the download is initiated via a user-facing consent prompt (AskUserQuestion) and uses checksum verification, it introduces a third-party binary into the local environment.
- [INDIRECT_PROMPT_INJECTION]: The skill's primary function involves ingesting and acting upon untrusted data from multiple sources. This represents a significant attack surface where malicious instructions could be embedded in processed content to influence the agent's code-modification behavior.
- Ingestion points: Project configuration and documentation files (
DESIGN.md,CLAUDE.md,TESTING.md), rendered DOM dumps from analyzed web pages, and results fromWebSearchandaside exectools. - Boundary markers: The headless browser wrapper (
$B) uses═══ BEGIN/END UNTRUSTED WEB CONTENT ═══markers to delimit untrusted output. However, other ingestion points like file reads lack explicit boundary protection in the provided instructions. - Capability inventory: The skill has broad capabilities including filesystem modification (
Write,Edit), shell access (Bash), and version control (git commit), which can be leveraged if an injection succeeds. - Sanitization: The skill utilizes a
gstack-redacttool to remove PII from DOM dumps before scanning, but it does not specify content-filtering mechanisms to prevent instruction injection from those files. - [COMMAND_EXECUTION]: Extensive use of shell commands is documented for environment setup, context recovery (using
find,grep,sed), and project management. These commands operate within the vendor's local state directories (~/.gstack/). - [DYNAMIC_EXECUTION]: The skill utilizes
aside replto execute JavaScript within a browser context andcodex execto perform remote code analysis. These tools are used for legitimate audit tasks but involve the dynamic execution of generated logic.
Audit Metadata