best-practices-design

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill contains a configuration in fixtures/agentic_eval.json that executes a local Python script (../../best-practices-skills/scripts/validate_skill.py). This command is intended for static validation of the skill contract within a development or testing environment.
  • [PROMPT_INJECTION]: The skill processes untrusted design inputs such as mockups and external screenshots, which serves as a potential surface for indirect prompt injection.
  • Ingestion points: Product UX direction, mockups, visual workflows, and external screenshots mentioned in SKILL.md.
  • Boundary markers: Absent; the instructions do not specify delimiters or warnings to ignore embedded text within these design artifacts.
  • Capability inventory: The skill primarily provides classification and routing logic; while it does not directly perform network or file operations, it composes other skills (e.g., best-practices-react, review-design) that may possess broader capabilities.
  • Sanitization: Absent; the skill does not define methods for validating or filtering instructions that might be embedded in user-provided design data.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:00 PM
Security Audit — agent-trust-hub — best-practices-design