creative-director
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: The skill documentation and YAML frontmatter (upstream field) refer to an external, third-party repository (github.com/smixs/creative-director-skill) for its full implementation and assets. It also instructs the agent to search for and utilize external plugins and MCP servers which are not pre-verified by the skill.
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest and act upon data from potentially untrusted external sources. 1. Ingestion points: The agent is directed to inspect HTML elements, browser tabs, design files, active design systems, and user-provided assets (SKILL.md). 2. Boundary markers: No instructions are provided to delimit these inputs or to ignore embedded instructions within them. 3. Capability inventory: The agent is authorized to interact with MCP servers, plugins, and generate visual assets based on the contents of the ingested data. 4. Sanitization: No sanitization, validation, or filtering of the external content is described.
Audit Metadata