critique
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill is instructed to run scripts defined in the target project's
package.jsonfile if they are configured for linting or design checks (Step 2, Assessment B). This behavior allows a malicious repository to execute arbitrary shell commands by embedding them within standard script fields that the agent is expected to run automatically during the critique process.- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the project being reviewed, which could be used to influence the agent's output or actions. - Ingestion points:
SKILL.md(Step 1) specifies reading source files (HTML, CSS, JS/TS),.impeccable.md, and.github/copilot-instructions.mdto gather brand and audience context. - Boundary markers: No specific delimiters or "ignore instructions" warnings are implemented when processing the content of these external files.
- Capability inventory: The skill has the capability to execute commands via
package.jsonscripts and manipulate browser session state (e.g., modifying document titles via browser automation). - Sanitization: No sanitization or validation of the ingested content is described before it is synthesized into the final report.- [DYNAMIC_EXECUTION]: The skill dynamically identifies and executes commands based on the contents of the project's local configuration files (
package.json) rather than using a static, pre-defined set of safe tools or commands.
Audit Metadata