thumb-first-design
Pass
Audited by Gen Agent Trust Hub on Jun 15, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection by ingesting untrusted data such as source code, screenshots, and URLs for analysis. Ingestion points: Ingestion occurs in 'workflows/audit.md' Step 1 during the design review process. Boundary markers: No explicit delimiters or instructions for the agent to ignore embedded instructions in the audited content are defined. Capability inventory: The skill utilizes file system writing, browser tools, and shell command execution to generate and display reports. Sanitization: No sanitization of the input data is specified in the workflows.
- [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands like 'open', 'xdg-open', or 'start' to view the generated HTML audit reports in the default browser. This is a functional feature of the skill used to provide the user with a rendered version of the findings.
Audit Metadata