design-md

Pass

Audited by Gen Agent Trust Hub on Jul 2, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill uses webfetch to download DESIGN.md files from a third-party GitHub repository (voltagent/awesome-design-md) for brands not bundled locally.
  • [PROMPT_INJECTION]: The skill implements an indirect prompt injection surface by ingesting untrusted data and granting it influence over agent logic.
  • Ingestion points: The skill fetches design guidelines from a remote URL (https://raw.githubusercontent.com/voltagent/awesome-design-md/...) and writes them to the local project root (./DESIGN.md).
  • Boundary markers: Absent. The instructions in SKILL.md explicitly tell the agent to "follow the Do's and Don'ts section of the DESIGN.md strictly" without any warnings to disregard potential embedded malicious instructions.
  • Capability inventory: The agent is directed to use these downloaded instructions to "build whatever the user requested," which involves using its primary code generation and project manipulation capabilities.
  • Sanitization: Absent. There is no validation or filtering of the content downloaded from the remote source before it is interpreted by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 2, 2026, 12:43 AM
Security Audit — agent-trust-hub — design-md