design-motion
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to ingest and analyze external UI code and design documents (e.g., files in the
_design/directory likeSIZING.mdandPROVENANCE.md). This ingestion of untrusted content, combined with the agent'sBashandWritecapabilities, creates a surface for indirect prompt injection where malicious instructions embedded in design files could influence agent actions.\n - Ingestion points: UI source code, design specifications, and project-specific documentation.\n
- Boundary markers: The skill uses HTML-style comments (e.g.,
<!-- design:contract -->,<!-- deliver:report -->) to define execution phases and separate concerns.\n - Capability inventory: The agent is granted
BashandWritetools, allowing it to execute local scripts and modify project files.\n - Sanitization: Verification is handled by checking claims against a fixed set of motion tokens and patterns, which provides structural validation but lacks explicit sanitization of text inputs.\n- [COMMAND_EXECUTION]: The instructions direct the agent to use a local script,
refute.py, to verify design claims. While this is a legitimate validation workflow, it relies on the presence of local executable code which could be a vector for malicious command execution if an attacker places a compromised version of the script in the project directory.
Audit Metadata