swiss-creative-mode-template
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it processes untrusted external design data to influence its output.
- Ingestion points: The workflow in
SKILL.mdrequires the agent to read an externalDESIGN.mdfile to map palette, typography, and layout decisions into CSS variables. - Boundary markers: No specific delimiters or "ignore embedded instructions" warnings are defined in
SKILL.mdfor the data read fromDESIGN.md. - Capability inventory: The skill utilizes the
file_writecapability to create theindex.htmlprimary output artifact. - Sanitization: There is no evidence of validation or sanitization protocols for the configuration values extracted from the external
DESIGN.mdfile before they are applied to the template.
Audit Metadata