hallmark
Pass
Audited by Gen Agent Trust Hub on Aug 22, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill provides a feature to "study" and extract design data from remote URLs. This functionality introduces an attack surface for indirect prompt injection, as malicious websites could host content designed to manipulate the AI agent's instructions or behavior.
- Ingestion points: Content is fetched from user-provided URLs using the
WebFetchtool during the design analysis process (SKILL.md, study.md). - Boundary markers: The skill instructs the agent to treat all fetched content as "untrusted inert data" to prevent obedience to embedded instructions (study.md).
- Capability inventory: The skill has the ability to read and modify local files including configuration, logs, and design systems, and can initiate outbound network requests via tools (SKILL.md, REDESIGN.md, study.md).
- Sanitization: Proactive instructions are included to ignore any embedded commands in remote HTML, CSS, or scripts, and to focus solely on extracting inert design facts (study.md).
- [EXTERNAL_DOWNLOADS]: The skill incorporates various external assets and encourages the integration of third-party libraries into user projects.
- Decorative assets and textures are referenced from a central imagery kit hosted at
https://www.usehallmark.com/imagery/(imagery-kit.md). - The skill recommends the use of established third-party resources such as Google Fonts, Fontshare, Lucide Icons, and Simple Icons for project styling (assets.md, typography.md).
Audit Metadata