design-review
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill requires the Bash tool and instructs the agent to execute local scripts and commands to render applications for review. Specifically, the 'seeing' playbook directs the agent to 'Find the entry point — a dev server script, a component explorer, a static build' and 'Start it'. It also references a local script 'refute.py'. These actions are necessary for the skill's primary function of visual review.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes external UI content and screenshots, which serves as an ingestion point for potentially malicious instructions embedded within the interfaces being reviewed.\n
- Ingestion points: UI renders and screenshots processed in the 'SEE' phase.\n
- Boundary markers: The skill uses a structured 'SEE -> IMPRESSION -> PRINCIPLE -> REFERENCE -> VERDICT' workflow but lacks explicit instructions to ignore text commands within the UI.\n
- Capability inventory: Access to Bash, Read, Grep, and Glob tools.\n
- Sanitization: The skill does not describe any sanitization or filtering of the visual or text data extracted from the target interfaces.
Audit Metadata