skills/system-desgin/agentds/carbon/Gen Agent Trust Hub

carbon

Warn

Audited by Gen Agent Trust Hub on Jul 21, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides a command to fetch design specifications from an external domain (api.agent-ds.oday-bakkour.com). While intended for refreshing design tokens, downloading content from unverified third-party domains introduces risk.
  • [COMMAND_EXECUTION]: The documentation includes executable commands for the user/agent: curl for downloading external content and npx for installing additional components from the author's registry (System-Desgin/AgentDS).
  • [PROMPT_INJECTION]: The skill creates an indirect prompt injection surface by instructing the agent to follow instructions from the DESIGN.md file exactly. Since this file can be updated from a remote source, it could potentially be used to inject malicious instructions.
  • Ingestion points: DESIGN.md and the remote URL https://api.agent-ds.oday-bakkour.com/v1/systems/carbon/design.md.
  • Boundary markers: Absent.
  • Capability inventory: The skill uses curl and npx, and performs file operations.
  • Sanitization: None identified.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 21, 2026, 02:55 PM
Security Audit — agent-trust-hub — carbon