reference-interpreter

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill interprets untrusted external content such as screenshots, images, or URLs which could contain malicious instructions designed to manipulate the model's output.
  • Ingestion points: Reference content (images, URLs, descriptions) processed during Phase 1 analysis (SKILL.md).
  • Boundary markers: Absent; the skill does not define specific delimiters or instructions to ignore commands embedded within the external reference data.
  • Capability inventory: The skill is intended to interact with Figma to create or modify design nodes and tokens, as indicated in the description and Phase 4.
  • Sanitization: No validation or sanitization of input data is mentioned before mapping to the design brief.
  • Mitigation: The design includes a mandatory human-in-the-loop step in Phase 4 that requires the user to type 'confirmed' before any tool execution occurs, which effectively prevents autonomous execution of injected instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 03:49 PM
Security Audit — agent-trust-hub — reference-interpreter