styleseed-design-review
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze external UI source files (React, Tailwind, HTML) which may contain attacker-controlled content.
- Ingestion points: Processes files or whole directories as specified in the "How to review" section.
- Boundary markers: Absent; the instructions do not define delimiters or provide guidance to the agent to ignore instructions embedded within the analyzed code.
- Capability inventory: The skill is limited to generating design scores and recommendations; it contains explicit instructions prohibiting automatic editing or deletion of files.
- Sanitization: Absent; there is no mention of filtering or escaping content from the processed files.
- [SAFE]: The skill serves as a static set of design guidelines. No evidence of hardcoded credentials, unauthorized network operations, obfuscation, or persistence mechanisms was found in the provided instructions. The inclusion of non-Latin characters (Korean text) in the rubric is used as a legitimate localization example and does not constitute a homoglyph attack.
Audit Metadata