design
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from user briefs and external references across all modes (e.g., SKILL.md, references/ui.md). These inputs are interpolated into the agent context to guide design decisions. Given the skill's access to powerful tools like bash and write_to_file, malicious instructions embedded in a brief could potentially influence the agent to perform unintended actions. Ingestion points: Intake gates defined in SKILL.md and each mode reference. Boundary markers: The skill uses structured procedures and quality gates but lacks explicit delimiters or ignore-previous-instructions warnings for user input. Capability inventory: Access to bash, view_file, write_to_file, replace_file_content, grep_search, and find_by_name. Sanitization: No explicit sanitization or validation of brief content is documented before processing.
- [COMMAND_EXECUTION]: The skill instructs the agent to use the bash tool for specific technical operations. For example, references/3d.md provides a command for asset optimization using gltfpack, and references/graphics.md mentions executing a generate.js script via Bash.
- [DYNAMIC_EXECUTION]: references/graphics.md references a tool-gated workflow involving the execution of a local generate.js script using Node.js and Bash, indicating that the skill is designed to interact with and execute external scripts at runtime.
Audit Metadata