art-director

Pass

Audited by Gen Agent Trust Hub on Aug 1, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches the dagre visualization library from the well-known jsDelivr CDN for rendering decision graphs in the HTML preview template.
  • [COMMAND_EXECUTION]: Instructs the agent to run a local Python HTTP server (python3 -m http.server 8080) to provide a preview environment for generated style-search maps.
  • [COMMAND_EXECUTION]: Utilizes various shell commands for project orchestration and validation, including directory creation (mkdir), file management (cp), and content verification (rg, test, git diff).
  • [PROMPT_INJECTION]: Ingests external reviewer feedback into the design process to create new style branches, which presents an indirect prompt injection surface. The skill incorporates instructions to use "safe summaries" and redacted feedback to manage this risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 1, 2026, 10:29 AM
Security Audit — agent-trust-hub — art-director