hallmark
Pass
Audited by Gen Agent Trust Hub on Jul 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes a local Python script located at
harness/scripts/design-variety.pyto maintain a log of design choices and ensure structural variety across different page builds. - [EXTERNAL_DOWNLOADS]: The
hallmark studyverb utilizes theWebFetchtool to retrieve HTML and CSS data from external URLs. This process includes explicit security checks to prevent access to local network resources, internal hostnames, and private IP address ranges. - [PROMPT_INJECTION]: The skill processes untrusted data from third-party websites during design extraction. The instructions in
references/study.mdprovide proactive defenses by directing the agent to treat all fetched content as inert data and to disregard any embedded instructions that attempt to override system protocols.
Audit Metadata