banner-design
Warn
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructions guide the agent to perform multiple shell operations using Python and Node.js where the command strings include variables derived from user input or agent-generated content. Without explicit sanitization instructions, these patterns create a risk of command injection.
- Evidence:
python3 .claude/skills/ai-artist/scripts/search.py "<banner style keywords>"in Step 3. - Evidence:
.claude/skills/ai-multimodal/scripts/gemini_batch_process.py --prompt "<banner visual prompt>"in Step 3. - Evidence:
node .claude/skills/chrome-devtools/scripts/screenshot.js --output "assets/banners/{campaign}/{variant}-{size}.png"in Step 4. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data and internal documentation that could influence the agent's logic during design and prompt generation.
- Ingestion points: Pinterest search results (Step 2) and
docs/brand-guidelines.md(Step 1). - Boundary markers: None specified for the interpolation of data from Pinterest or brand documents into design prompts or HTML code.
- Capability inventory: Shell execution (python/node), file writing to the
assets/directory, and browser control viachrome-devtools. - Sanitization: The instructions lack guidance for sanitizing research data before it is used to construct prompts for the
ai-artistorai-multimodaltools.
Audit Metadata