orshot-design
Pass
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection vulnerability surface.
- Ingestion points: The skill ingests potentially untrusted data from the brand kit and existing templates via the
orshot_get_brand_kitandorshot_get_studio_templatetools as specified in theSKILL.mdworkflow. - Boundary markers: There are no explicit markers or instructions defined to isolate or disregard instructions that might be embedded within the retrieved brand colors, fonts, or template content.
- Capability inventory: The skill has the capability to perform creation and modification tasks using
orshot_create_template_designandorshot_patch_template_elements, which could be influenced by the ingested data. - Sanitization: No sanitization or validation mechanisms are implemented for the content fetched from the MCP tools before it is used in design generation.
Audit Metadata