skills/simota/agent-skills/atelier/Gen Agent Trust Hub

atelier

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill operates as a high-level orchestrator that ingests potentially untrusted data from external sources and propagates it to downstream agents with significant capabilities.
  • Ingestion points: Untrusted data enters the agent context via Figma file extractions (delegated to Frame), codebase scans for existing design tokens (delegated to Muse), and aesthetic briefs from the user or the Vision agent.
  • Capability inventory: The skill has the authority to spawn multiple sub-agents (Artisan, Forge, Pixel, etc.) and perform file-write operations to the .agents/ directory for persisting design system state and logging activity.
  • Boundary markers: The skill uses a structured DESIGN_INTENT_HANDOFF schema and defined operation layers (parametric sliders, structured comments) which act as structural boundaries, but these do not prevent the semantic injection of instructions within the data fields.
  • Sanitization: There is no evidence of semantic filtering or sanitization of the design data (e.g., token names, component descriptions) before it is interpolated into instructions for downstream implementation agents.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 01:48 PM
Security Audit — agent-trust-hub — atelier