design-ux
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill architecture is designed to ingest and process user-provided design "briefs" and "research" data to generate interaction specifications and flows. \n
- Ingestion points: Input is ingested via the sizing process and evaluating research data as described in
SKILL.md. \n - Boundary markers: Absent; there are no instructions for the agent to distinguish between valid design requirements and potentially malicious commands embedded in these external sources. \n
- Capability inventory: The skill utilizes
Bash,Read, andWritetools as defined inSKILL.md, providing a surface where malicious input could lead to unauthorized file changes or script execution. \n - Sanitization: Absent; the skill does not specify any validation or sanitization logic for content ingested from external documents. \n- [COMMAND_EXECUTION]: The
SKILL.mdfile references a local script namedrefute.pyas a tool for validating design claims. This script is not provided in the skill package, constituting an unverifiable local dependency that the agent is instructed to use.
Audit Metadata