claude-design

Pass

Audited by Gen Agent Trust Hub on Jul 15, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill contains explicit instructions for the agent to handle and ignore prompt injection attempts that might be found in untrusted external web content (e.g., from WebSearch or fetched URLs). This is a security mitigation, not a vulnerability.
  • [EXTERNAL_DOWNLOADS]: The skill utilizes unpkg.com to load frontend libraries such as React and Babel for its prototyping features. These references include Subresource Integrity (SRI) hashes (e.g., integrity="sha384-..."), which is a security best practice to ensure the integrity of externally hosted files.
  • [DATA_EXFILTRATION]: No patterns of sensitive data exfiltration or unauthorized network communication were found. The skill's network operations (WebSearch and asset downloads) are central to its intended design purpose and target legitimate brand/official sources.
  • [COMMAND_EXECUTION]: The skill instructs the agent on the use of standard command-line tools like curl, wget, yt-dlp, and ffmpeg for the legitimate purpose of downloading and processing design assets (logos, product photography, and video frames).
  • [INDIRECT_PROMPT_INJECTION]: While the skill ingests untrusted data from the internet, it includes mandatory evidence of sanitization and boundary instructions. It explicitly tells the agent to 'stop and report' if fetched content contains instruction-like text directed at the agent, effectively mitigating this attack vector.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 15, 2026, 02:39 PM
Security Audit — agent-trust-hub — claude-design