information-architecture-and-navigation
Warn
Audited by Gen Agent Trust Hub on Jun 25, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to fetch and install external code from the 'jpoindexter/design-and-ai-skills' GitHub repository. This source is not a verified or trusted vendor, posing a risk of executing unvetted third-party instructions.
- [COMMAND_EXECUTION]: The 'Decision tree' section contains shell commands using
grepandnpxto check for and perform skill installation. It explicitly encourages the agent to use the '!' command prefix, which in some environments triggers immediate shell execution, to automate the installation process without manual user entry. - [PROMPT_INJECTION]: The skill's instructions guide the agent to modify its own environment by installing external content, which can be used to bypass initial skill constraints and introduce new, potentially malicious behaviors from the upstream source.
Audit Metadata