skills/openai/plugins/audit/Gen Agent Trust Hub

audit

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [Indirect Prompt Injection Considerations]: The skill processes live content from websites and Figma files to generate audit reports. As the agent interprets this external data, it represents a surface where untrusted content is ingested into the agent's context. \n
  • Ingestion points: Target product URLs, web page DOM, and Figma board content (SKILL.md). \n
  • Boundary markers: The skill uses specific design 'lenses' and framework structures to focus the analysis, helping to constrain the model's interpretation of external data (references/design-audit-framework.md). \n
  • Capability inventory: The agent has access to browser controls, local file storage, and Figma API integration to perform its tasks. \n
  • Sanitization: The skill produces human-readable reports and does not appear to execute instructions derived directly from the captured data. \n- [Local Script Execution]: The skill includes instructions to run a preflight script from a related local skill (user-context). This is a functional procedure used to ground the audit in the user's specific environment and settings. \n- [Third-Party Service Integration]: Audit evidence and findings can be exported to Figma. This process involves transferring captured screenshots and notes to an external platform to complete the audit workflow as requested by the user.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:21 AM
Security Audit — agent-trust-hub — audit