stitch-design-taste

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection by design, as it instructs the agent to adapt the generated DESIGN.md based on a user's "vibe description".\n
  • Ingestion points: User-supplied design and atmosphere descriptions processed in SKILL.md.\n
  • Boundary markers: The instructions lack explicit delimiters or instructions to treat user input as untrusted content, which could allow a malicious description to influence agent behavior beyond design generation.\n
  • Capability inventory: The skill is limited to text generation for design documentation; it does not involve tool calls, shell execution, or network exfiltration using the user data.\n
  • Sanitization: No input validation or sanitization routines are specified for the user's vibe description.\n- [SAFE]: The skill includes references to labs.google.com and placeholder image services like picsum.photos. These are recognized as trusted and well-known services used for legitimate design purposes and do not pose a security risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 01:28 PM
Security Audit — agent-trust-hub — stitch-design-taste