import-screenshot-to-prototype

Pass

Audited by Gen Agent Trust Hub on Aug 31, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied images as input, which constitutes an ingestion point for untrusted data.
  • Ingestion points: User-provided screenshots or image references (SKILL.md).
  • Boundary markers: None explicitly defined to separate visual content from instructions.
  • Capability inventory: The skill has file-writing capabilities (fs:write) to generate index.html artifacts.
  • Sanitization: No specific visual sanitization is mentioned to prevent instructions embedded within images from being interpreted as agent commands.
  • [SAFE]: The skill instructions and configuration define a legitimate workflow for UI prototyping. The manifest file (open-design.json) correctly scopes its capabilities to file system access and internal prompt injection for the critique loop, and no suspicious behaviors such as network operations or credential harvesting were found.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 31, 2026, 01:19 PM
Security Audit — agent-trust-hub — import-screenshot-to-prototype