hallmark

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill uses a WebFetch tool to retrieve HTML and CSS from user-supplied URLs to perform design analysis (hallmark study). It implements a detailed 'Remote URL Safety' protocol that blocks access to local networks, private IP ranges, and unauthorized schemes.
  • [PROMPT_INJECTION]: The skill identifies the inherent risk of indirect prompt injection when processing external web content. It includes explicit instructions for the AI agent to treat all fetched content as untrusted data and to ignore any instructions or behavioral overrides embedded in remote metadata, comments, or visible copy (Category 8).
  • Ingestion points: hallmark study <URL> triggers a fetch of remote HTML/CSS content.
  • Boundary markers: Present; the instructions mandate treating remote data as inert facts for extraction only.
  • Capability inventory: The skill is authorized to perform file operations (writing tokens.css, design.md, and log files) and can invoke web-fetching tools.
  • Sanitization: The instructions require the agent to ignore remote commands and extract only design-related facts.
  • [EXTERNAL_DOWNLOADS]: The skill references and integrates with several well-known design and asset services including Google Fonts, Fontshare, Unsplash, Simple Icons, and Lucide to provide resources for user projects.
  • [COMMAND_EXECUTION]: The skill generates implementation code for frontend projects, including CSS, React components, and Node.js package dependency lists. These are provided as output for the user's codebase and are not executed by the skill itself in a malicious context.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 01:28 PM
Security Audit — agent-trust-hub — hallmark