design-direction
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external 'references' such as links, screenshots, and brand identities, which act as ingestion points for untrusted data. Ingestion points: Reference collection is outlined in
SKILL.mdand detailed inplaybooks/reference-analysis.md. Boundary markers: No formal prompt boundaries or 'ignore embedded instructions' warnings are present for external content. Capability inventory: The skill allows access toBash,Write,Read,Grep, andGlobtools, providing a wide surface for exploitation if instructions are injected. Sanitization: The skill lacks explicit sanitization or validation logic for the external references. - [REMOTE_CODE_EXECUTION]: The skill instructions in
SKILL.mdreference a script namedrefute.pyto be used for validating design choices. This script is missing from the skill manifest. Evidence:SKILL.mdcontains a table entry linking to[refute](refute.py)for evaluating expensive design claims. Risk: Since the agent is grantedBashtool access, it may attempt to execute this missing script. If a script with this name exists in the environment or is introduced by an attacker, it represents an unverified code execution path.
Audit Metadata