design-critique

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external artifacts, such as screenshots, code, and live UI elements, which serve as ingestion points for potentially malicious data.
  • Ingestion points: Artifacts (screenshots, code, live URLs), design briefs, and project specifications are ingested from external sources for review.
  • Boundary markers: The skill lacks explicit instructions to ignore or sanitize embedded commands within the artifacts being reviewed, though it does require establishing a named standard first.
  • Capability inventory: The skill is allowed to use Bash, Read, Grep, and Glob tools. While Bash provides high capability, the skill is strictly report-only and prohibited from editing artifacts or producing replacements.
  • Sanitization: There are no documented sanitization or escaping mechanisms for content extracted from the analyzed artifacts before it is processed by the agent.
  • [DATA_EXFILTRATION]: The skill instructions suggest gathering data from live UI or scanning the stylesheet, which implies network operations to external domains using the Bash tool.
  • Evidence: The playbooks/craft-audit.md file advises gathering inventory from a live UI using DevTools or by scanning the stylesheet.
  • Risk: This capability involves making network requests to arbitrary external domains to fetch assets for audit purposes, which constitutes a low-severity network operation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 10:23 AM
Security Audit — agent-trust-hub — design-critique