skills/leonardomso/website/impeccable/Gen Agent Trust Hub

impeccable

Pass

Audited by Gen Agent Trust Hub on Aug 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill represents a surface for indirect prompt injection because it reads and processes data from potentially untrusted project files to drive its design and audit logic. • Ingestion points: The skill reads PRODUCT.md, DESIGN.md, and application source code files (HTML, CSS, JS/TS). • Boundary markers: It uses specific markdown comments, such as and , to delimit AI-generated content within source files. • Capability inventory: The skill has the capability to execute local Node.js scripts, perform file system writes to modify project source code, and interact with the user's browser via automation. • Sanitization: There are no explicitly documented measures for sanitizing or escaping instructions that might be embedded within the project files it processes.
  • [COMMAND_EXECUTION]: The skill frequently executes local Node.js scripts (e.g., load-context.mjs, live.mjs, pin.mjs) to manage project state and perform UI iterations. These scripts are contained within the skill's own internal directory structure.
  • [EXTERNAL_DOWNLOADS]: The skill uses npx to execute the impeccable package, which is the core engine for its auditing and live iteration features. This package is managed by the skill's author. Additionally, the skill suggests the use of stock imagery from Unsplash, a well-known and trusted service, for placeholders during the design process.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 17, 2026, 11:03 AM
Security Audit — agent-trust-hub — impeccable