lp-designer

Pass

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes shell commands to manage project deployment and environment setup, specifically utilizing the Vercel CLI and npm (e.g., npm i -g vercel, vercel --prod).
  • [EXTERNAL_DOWNLOADS]: Fetches the Vercel CLI from the official npm registry and the Tailwind CSS framework from a well-known CDN (cdn.tailwindcss.com) during the implementation phase.
  • [PROMPT_INJECTION]: The skill identifies an indirect prompt injection surface by requesting reference URLs from the user to inform the design process.
  • Ingestion points: Phase 1-3 in SKILL.md, SKILL.en.md, and SKILL.es.md (Reference site URLs).
  • Boundary markers: Absent; no specific instructions are provided to the agent to treat external site content as untrusted or to ignore embedded instructions.
  • Capability inventory: The skill possesses capabilities for file system modification (creating project files), shell command execution (Vercel CLI), and GUI manipulation via the Pencil MCP.
  • Sanitization: Absent; there is no logic described for filtering or validating content extracted from user-provided URLs.
Audit Metadata
Risk Level
SAFE
Analyzed
May 14, 2026, 05:59 AM
Security Audit — agent-trust-hub — lp-designer