reference-interpreter
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill interprets untrusted external content such as screenshots, images, or URLs which could contain malicious instructions designed to manipulate the model's output.
- Ingestion points: Reference content (images, URLs, descriptions) processed during Phase 1 analysis (SKILL.md).
- Boundary markers: Absent; the skill does not define specific delimiters or instructions to ignore commands embedded within the external reference data.
- Capability inventory: The skill is intended to interact with Figma to create or modify design nodes and tokens, as indicated in the description and Phase 4.
- Sanitization: No validation or sanitization of input data is mentioned before mapping to the design brief.
- Mitigation: The design includes a mandatory human-in-the-loop step in Phase 4 that requires the user to type 'confirmed' before any tool execution occurs, which effectively prevents autonomous execution of injected instructions.
Audit Metadata