best-practices-design
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill contains a configuration in
fixtures/agentic_eval.jsonthat executes a local Python script (../../best-practices-skills/scripts/validate_skill.py). This command is intended for static validation of the skill contract within a development or testing environment. - [PROMPT_INJECTION]: The skill processes untrusted design inputs such as mockups and external screenshots, which serves as a potential surface for indirect prompt injection.
- Ingestion points: Product UX direction, mockups, visual workflows, and external screenshots mentioned in
SKILL.md. - Boundary markers: Absent; the instructions do not specify delimiters or warnings to ignore embedded text within these design artifacts.
- Capability inventory: The skill primarily provides classification and routing logic; while it does not directly perform network or file operations, it composes other skills (e.g.,
best-practices-react,review-design) that may possess broader capabilities. - Sanitization: Absent; the skill does not define methods for validating or filtering instructions that might be embedded in user-provided design data.
Audit Metadata