visual-composition
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process and interpret user-supplied conceptual threads and "subtle input" to generate visual layouts and design philosophies, creating a potential surface for indirect injection.
- Ingestion points: User instructions and niche conceptual references described in the "DEDUCING THE SUBTLE REFERENCE" section of SKILL.md.
- Boundary markers: Absent; the skill lacks specific delimiters or instructions to ignore potentially malicious directions embedded within user-supplied conceptual data.
- Capability inventory: The skill is capable of writing multiple file types including .md, .pdf, and .png, and is directed to download/use font resources.
- Sanitization: No sanitization or validation of the conceptual inputs is implemented.
- [PROMPT_INJECTION]: The instructions utilize simulated user feedback ("The user ALREADY said 'It isn't perfect enough...' ") and highly imperative language ("CRITICAL", "non-negotiable", "STOP and instead ask") to override default agent behavior and enforce a strict "expert craftsman" persona for stylistic consistency.
Audit Metadata