atelier
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill operates as a high-level orchestrator that ingests potentially untrusted data from external sources and propagates it to downstream agents with significant capabilities.
- Ingestion points: Untrusted data enters the agent context via Figma file extractions (delegated to
Frame), codebase scans for existing design tokens (delegated toMuse), and aesthetic briefs from the user or theVisionagent. - Capability inventory: The skill has the authority to spawn multiple sub-agents (
Artisan,Forge,Pixel, etc.) and perform file-write operations to the.agents/directory for persisting design system state and logging activity. - Boundary markers: The skill uses a structured
DESIGN_INTENT_HANDOFFschema and defined operation layers (parametric sliders, structured comments) which act as structural boundaries, but these do not prevent the semantic injection of instructions within the data fields. - Sanitization: There is no evidence of semantic filtering or sanitization of the design data (e.g., token names, component descriptions) before it is interpolated into instructions for downstream implementation agents.
Audit Metadata