design-motion

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to ingest and analyze external UI code and design documents (e.g., files in the _design/ directory like SIZING.md and PROVENANCE.md). This ingestion of untrusted content, combined with the agent's Bash and Write capabilities, creates a surface for indirect prompt injection where malicious instructions embedded in design files could influence agent actions.\n
  • Ingestion points: UI source code, design specifications, and project-specific documentation.\n
  • Boundary markers: The skill uses HTML-style comments (e.g., <!-- design:contract -->, <!-- deliver:report -->) to define execution phases and separate concerns.\n
  • Capability inventory: The agent is granted Bash and Write tools, allowing it to execute local scripts and modify project files.\n
  • Sanitization: Verification is handled by checking claims against a fixed set of motion tokens and patterns, which provides structural validation but lacks explicit sanitization of text inputs.\n- [COMMAND_EXECUTION]: The instructions direct the agent to use a local script, refute.py, to verify design claims. While this is a legitimate validation workflow, it relies on the presence of local executable code which could be a vector for malicious command execution if an attacker places a compromised version of the script in the project directory.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 10:23 AM
Security Audit — agent-trust-hub — design-motion