frontend-design
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands using the
Bashtool to read and filter local files. Evidence:cat .claude/context/memory/learnings.md | grep -i "design\|ui\|frontend\|css"inSKILL.md. - [INDIRECT_PROMPT_INJECTION]: The skill has a surface for indirect prompt injection because it ingests data from local memory files that could potentially contain instructions from previously processed untrusted data.
- Ingestion points:
.claude/context/memory/learnings.md(read via bash inSKILL.md). - Boundary markers: None identified in the instructions to distinguish between retrieved memory and system instructions.
- Capability inventory: The skill has access to
Bash,Read,Write,Edit,Glob, andGreptools. - Sanitization: No sanitization or validation of the retrieved memory content is mentioned.
Audit Metadata