review-design
Warn
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: MEDIUMCREDENTIALS_UNSAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The orchestrator script
review_design.pyprogrammatically retrieves theGEMINI_API_KEYfrom the system's KDE Wallet (kdewallet) using thekwallet-queryutility. This method allows the skill to access sensitive credentials stored in the local password manager without explicit user consent for each execution. - [COMMAND_EXECUTION]: The skill uses
subprocess.runto execute external binaries includingkwallet-queryand theopenaiCLI. These calls are used to fetch secrets and interact with vision providers. This pattern introduces a risk of command injection if path names or environment variables are manipulated. - [DATA_EXFILTRATION]: Local source code files (e.g.,
.qml,.css,.tsx) are automatically discovered by walking up parent directories from the user-provided screenshots folder. The contents of these files are extracted and sent to external LLM providers as 'Implementation Code Context'. While this supports the design review process, it results in the transmission of local intellectual property to third-party services. - [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it ingests untrusted data from screenshots and local files and interpolates it into prompts without sanitization.
- Ingestion points: Reads files from the
screenshots_dirand implementation files discovered viafind_implementation_filesinreview_design.py. - Boundary markers: None; the prompts in
prompts.pyuse basic Markdown blocks which can be subverted by malicious content within the analyzed files. - Capability inventory: Execution of system commands via
subprocess.runacross multiple files. - Sanitization: No validation, filtering, or escaping is performed on the content read from the file system before it is sent to the vision models.
Audit Metadata