review-design

Warn

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: MEDIUMCREDENTIALS_UNSAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The orchestrator script review_design.py programmatically retrieves the GEMINI_API_KEY from the system's KDE Wallet (kdewallet) using the kwallet-query utility. This method allows the skill to access sensitive credentials stored in the local password manager without explicit user consent for each execution.
  • [COMMAND_EXECUTION]: The skill uses subprocess.run to execute external binaries including kwallet-query and the openai CLI. These calls are used to fetch secrets and interact with vision providers. This pattern introduces a risk of command injection if path names or environment variables are manipulated.
  • [DATA_EXFILTRATION]: Local source code files (e.g., .qml, .css, .tsx) are automatically discovered by walking up parent directories from the user-provided screenshots folder. The contents of these files are extracted and sent to external LLM providers as 'Implementation Code Context'. While this supports the design review process, it results in the transmission of local intellectual property to third-party services.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it ingests untrusted data from screenshots and local files and interpolates it into prompts without sanitization.
  • Ingestion points: Reads files from the screenshots_dir and implementation files discovered via find_implementation_files in review_design.py.
  • Boundary markers: None; the prompts in prompts.py use basic Markdown blocks which can be subverted by malicious content within the analyzed files.
  • Capability inventory: Execution of system commands via subprocess.run across multiple files.
  • Sanitization: No validation, filtering, or escaping is performed on the content read from the file system before it is sent to the vision models.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 17, 2026, 06:37 AM
Security Audit — agent-trust-hub — review-design