designscope
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted web content and Figma data, creating a potential surface for indirect prompt injection where malicious instructions could be embedded in analyzed materials. * Ingestion points: External data is retrieved via the
web_fetchtool and Figma MCP tools, and processed by scripts likescripts/extract_css_vars.py. * Boundary markers: The procedure in SKILL.md does not explicitly instruct the agent to use delimiters or ignore instructions found within the fetched data. * Capability inventory: The skill has access tobashfor running scripts andwrite_to_filefor generating design artifacts, which could be misused if an injection is successful. * Sanitization: Extraction scripts use specific regular expressions to filter for CSS variables, providing a degree of structural validation for incoming data. - [EXTERNAL_DOWNLOADS]: The skill retrieves HTML and CSS files from user-provided URLs using the
web_fetchtool and Python'surlliblibrary. This is a functional requirement for analyzing external design systems. - [COMMAND_EXECUTION]: The skill uses the
bashtool to execute several local Python scripts included in the repository, such ascheck_contrast.pyandlint_design_md.py, to process and validate design data.
Audit Metadata