frontend-design
Pass
Audited by Gen Agent Trust Hub on Mar 22, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The
SKILL (1).mdfile contains instructions that override the agent's natural behavior by asserting that the user has already expressed dissatisfaction ('The user ALREADY said...'). This technique is used to force the agent into a specific high-effort persona and bypass normal response variation. - [PROMPT_INJECTION]: The skill uses repetitive, high-pressure language (e.g., 'CRITICAL', 'IMPORTANT', 'NON-NEGOTIABLE') to override the agent's default safety or quality parameters in favor of its own aesthetic constraints.
- [PROMPT_INJECTION]: The skill lacks sufficient sanitization and boundary markers for processing untrusted user data. Ingestion points: User frontend requirements in
SKILL.mdand visual input inSKILL (1).md. Boundary markers: Absent. Capability inventory: Generation and execution of frontend code (HTML/CSS/JS/React) and creation of PDF/PNG artifacts. Sanitization: No explicit validation or escaping mentioned for user-provided context. - [EXTERNAL_DOWNLOADS]: The
SKILL (1).mdfile directs the agent to 'Download and use whatever fonts are needed', which involves fetching data from unspecified and unvalidated remote sources.
Audit Metadata