design-review

Pass

Audited by Gen Agent Trust Hub on Apr 5, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute a shell command using python3 -c to perform accessibility calculations with code that is constructed at runtime using application data.
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection (Category 8) because it processes content from external live applications and uses it to populate executable code.
  • Ingestion points: Data from the 'Dashboard', 'data list pages', and 'form pages' of the live application under review (SKILL.md).
  • Boundary markers: None specified to differentiate application data from agent instructions.
  • Capability inventory: Local shell command execution via the python3 -c command (SKILL.md).
  • Sanitization: No validation or sanitization of the extracted color hex codes is mentioned before they are interpolated into the Python script template.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 5, 2026, 12:44 AM
Security Audit — agent-trust-hub — design-review