design-critique
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external artifacts, such as screenshots, code, and live UI elements, which serve as ingestion points for potentially malicious data.
- Ingestion points: Artifacts (screenshots, code, live URLs), design briefs, and project specifications are ingested from external sources for review.
- Boundary markers: The skill lacks explicit instructions to ignore or sanitize embedded commands within the artifacts being reviewed, though it does require establishing a named standard first.
- Capability inventory: The skill is allowed to use Bash, Read, Grep, and Glob tools. While Bash provides high capability, the skill is strictly report-only and prohibited from editing artifacts or producing replacements.
- Sanitization: There are no documented sanitization or escaping mechanisms for content extracted from the analyzed artifacts before it is processed by the agent.
- [DATA_EXFILTRATION]: The skill instructions suggest gathering data from live UI or scanning the stylesheet, which implies network operations to external domains using the Bash tool.
- Evidence: The playbooks/craft-audit.md file advises gathering inventory from a live UI using DevTools or by scanning the stylesheet.
- Risk: This capability involves making network requests to arbitrary external domains to fetch assets for audit purposes, which constitutes a low-severity network operation.
Audit Metadata