design-taste-frontend

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides installation and usage instructions for official design systems and component libraries from trusted organizations, including Google (@material/web), Microsoft (@fluentui/react-components), IBM (@carbon/react), Vercel (@radix-ui/themes, shadcn/ui), GitHub (@primer/css), and Shopify (polaris.js). It also references well-known assets from Simple Icons and Picsum Photos for placeholders.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and interpret external design briefs and analyze linked URLs to determine a project's aesthetic direction (SKILL.md, Section 0.A). While the agent has significant capabilities, such as React code generation and image generation using environment-specific tools (SKILL.md, Sections 3.A and 4.8), there are no explicit boundary markers or sanitization procedures described to isolate instructions potentially hidden in user-provided briefs or external web content from the agent's instructions. This creates a standard ingestion surface for indirect prompt injection.
  • [PROMPT_INJECTION]: The skill includes strong, non-negotiable instructions intended to override the agent's default stylistic choices, such as a total ban on em-dashes and specific "AI-default" color palettes (SKILL.md, Section 9.G and 4.2). These directives are stylistic in nature and serve the skill's primary purpose of ensuring high-quality design output rather than attempting to bypass safety filters.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 12:17 PM
Security Audit — agent-trust-hub — design-taste-frontend