rico-design-md

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external, untrusted website URLs to generate design system documentation. This creates a surface where malicious instructions embedded in a target website's text or metadata could influence the agent's behavior.
  • Ingestion points: External website content, CSS variables, and visual data are extracted from user-provided URLs as described in the 'Gather Visual Data' and 'Extract Tokens' steps in SKILL.md.
  • Boundary markers: The instructions lack explicit boundary markers or 'ignore embedded instructions' warnings for the data being parsed from external sites.
  • Capability inventory: The agent has the capability to write multiple files to the local file system (DESIGN.md, preview.html, tokens.json, variables.css, theme.css).
  • Sanitization: There are no specific instructions to sanitize or escape the content extracted from external sites before it is written into the generated documents, which could lead to the propagation of malicious text or script snippets into the output files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 08:26 AM
Security Audit — agent-trust-hub — rico-design-md