adhd-design-expert
Pass
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: Indirect Prompt Injection Surface. The skill is designed to ingest data from untrusted external sources, which creates a surface for potential indirect instructions.\n
- Ingestion points: Untrusted data enters the agent context via the
mcp__firecrawl__firecrawl_searchtool and theReadtool for accessing file content.\n - Boundary markers: The instructions do not include explicit delimiters or safety prompts to ignore instructions embedded in the processed data.\n
- Capability inventory: The skill possesses significant capabilities including
Write,Edit, andmcp__magic__21st_magic_component_builder, which could be targeted by a successful injection.\n - Sanitization: No explicit sanitization or validation of external content is specified in the skill's logic or design workflow.
Audit Metadata