banner-design

Warn

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructions guide the agent to perform multiple shell operations using Python and Node.js where the command strings include variables derived from user input or agent-generated content. Without explicit sanitization instructions, these patterns create a risk of command injection.
  • Evidence: python3 .claude/skills/ai-artist/scripts/search.py "<banner style keywords>" in Step 3.
  • Evidence: .claude/skills/ai-multimodal/scripts/gemini_batch_process.py --prompt "<banner visual prompt>" in Step 3.
  • Evidence: node .claude/skills/chrome-devtools/scripts/screenshot.js --output "assets/banners/{campaign}/{variant}-{size}.png" in Step 4.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data and internal documentation that could influence the agent's logic during design and prompt generation.
  • Ingestion points: Pinterest search results (Step 2) and docs/brand-guidelines.md (Step 1).
  • Boundary markers: None specified for the interpolation of data from Pinterest or brand documents into design prompts or HTML code.
  • Capability inventory: Shell execution (python/node), file writing to the assets/ directory, and browser control via chrome-devtools.
  • Sanitization: The instructions lack guidance for sanitizing research data before it is used to construct prompts for the ai-artist or ai-multimodal tools.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 1, 2026, 02:06 PM