moai-domain-design-dna
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill retrieves and analyzes data from external URLs and user-provided images, creating an ingestion point for potentially untrusted content.
- Ingestion points: Phase 2 (Analyze) uses the
WebFetchtool to retrieve data from reference URLs and processes visual data from images. - Boundary markers: The instructions do not specify the use of boundary markers or instructions to disregard potential commands found within the external data.
- Capability inventory: The skill is configured with access to
Write,Edit, andBashtools in its execution environment. - Sanitization: There are no explicit requirements for sanitizing or validating the content fetched from external sources before the agent processes it.
- [EXTERNAL_DOWNLOADS]: The skill fetches assets and well-known animation libraries from external sources to support design generation.
- Evidence: Phase 3 instructs the agent to download original assets like logos and fonts from the reference design URL.
references/effects-implementation.mdrefers to using established libraries like GSAP and Lottie from CDNs.
Audit Metadata