design-taste-frontend

Pass

Audited by Gen Agent Trust Hub on Jul 16, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill uses strong, imperative language to override default agent behaviors (e.g., "MANDATORY", "BANNED", "NON-NEGOTIABLE", "OVERRIDE"). These instructions function as a persona-enforcement mechanism rather than a malicious bypass of model safety guidelines.
  • [COMMAND_EXECUTION]: The skill provides instructions for the agent to execute shell commands for project initialization and package management, such as npm install and npx shadcn@latest. These are standard developer workflows for the intended use case.
  • [EXTERNAL_DOWNLOADS]: The skill references and encourages the use of various third-party design systems and assets from official or well-known sources (e.g., GitHub, Google, Microsoft, Vercel, IBM, and Simple Icons). These are documented neutrally as they originate from trusted or well-known technology providers.
  • [DATA_EXPOSURE]: The skill instructs the agent to analyze user-provided data, such as project briefs, URLs, and screenshots. This constitutes an entry point for untrusted external data that the agent must process.
  • [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its core functionality of processing untrusted external inputs.
  • Ingestion points: Section 0 ('BRIEF INFERENCE') specifies that the agent reads user-provided briefs, URLs, and screenshots.
  • Boundary markers: No explicit delimiters or boundary markers are defined to isolate the untrusted brief from the agent's instructions.
  • Capability inventory: The skill utilizes shell execution for package management (npm, npx) and interacts with image generation tools.
  • Sanitization: There is no evidence of sanitization or validation of the untrusted inputs provided in the project brief.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 16, 2026, 03:20 AM
Security Audit — agent-trust-hub — design-taste-frontend