design-md
Pass
Audited by Gen Agent Trust Hub on Jul 2, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill uses
webfetchto downloadDESIGN.mdfiles from a third-party GitHub repository (voltagent/awesome-design-md) for brands not bundled locally. - [PROMPT_INJECTION]: The skill implements an indirect prompt injection surface by ingesting untrusted data and granting it influence over agent logic.
- Ingestion points: The skill fetches design guidelines from a remote URL (
https://raw.githubusercontent.com/voltagent/awesome-design-md/...) and writes them to the local project root (./DESIGN.md). - Boundary markers: Absent. The instructions in
SKILL.mdexplicitly tell the agent to "follow the Do's and Don'ts section of the DESIGN.md strictly" without any warnings to disregard potential embedded malicious instructions. - Capability inventory: The agent is directed to use these downloaded instructions to "build whatever the user requested," which involves using its primary code generation and project manipulation capabilities.
- Sanitization: Absent. There is no validation or filtering of the content downloaded from the remote source before it is interpreted by the agent.
Audit Metadata