moai-domain-design-dna

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill retrieves and analyzes data from external URLs and user-provided images, creating an ingestion point for potentially untrusted content.
  • Ingestion points: Phase 2 (Analyze) uses the WebFetch tool to retrieve data from reference URLs and processes visual data from images.
  • Boundary markers: The instructions do not specify the use of boundary markers or instructions to disregard potential commands found within the external data.
  • Capability inventory: The skill is configured with access to Write, Edit, and Bash tools in its execution environment.
  • Sanitization: There are no explicit requirements for sanitizing or validating the content fetched from external sources before the agent processes it.
  • [EXTERNAL_DOWNLOADS]: The skill fetches assets and well-known animation libraries from external sources to support design generation.
  • Evidence: Phase 3 instructs the agent to download original assets like logos and fonts from the reference design URL. references/effects-implementation.md refers to using established libraries like GSAP and Lottie from CDNs.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 10:47 PM
Security Audit — agent-trust-hub — moai-domain-design-dna