logo-design
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted user input, such as brand names and descriptions, to guide the design process. This is a functional requirement for the skill's primary purpose.
- Ingestion points: Phase 1 (Discovery) instructions in
SKILL.mdwhere the agent is prompted to learn brand details from the user. - Boundary markers: The skill does not explicitly instruct the agent to use delimiters or specific ignore-previous-instructions warnings when processing this user input.
- Capability inventory: The skill can execute local Python scripts via the shell and perform various file system operations (reading reference SVGs from the library, writing design iterations, and generating export variants).
- Sanitization: No specific sanitization or filtering of user-provided strings is mentioned in the instructions, although the agent's controlled usage of these strings (e.g., for visual concept generation rather than direct execution logic) provides inherent mitigation.
- [COMMAND_EXECUTION]: The skill instructs the agent to execute several local Python scripts (e.g.,
svg_audit.py,render_png.py,preview_sheet.py) to perform technical design tasks. The instructions ensure the agent manages the filenames passed as arguments, reducing the risk of injection from user-supplied strings.
Audit Metadata