method-figure-loop
Warn
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: MEDIUMPROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill includes explicit instructions in Phase 4 intended for a secondary reviewer model that command it to ignore standard safety and defensive behaviors. Specifically, the prompt includes directives such as 'No over-defense,' 'No defensive scaffolding,' and 'no caveat sprinkling' to force blunt feedback, which functions as an instruction override for the sub-agent.
- [COMMAND_EXECUTION]: The instructions in Phase 3 provide shell commands to be executed via the
Bashtool. These commands launch a local browser (Microsoft Edge) in headless mode to capture screenshots of generated files and use--dump-domto export SVG content to the local filesystem. - [DYNAMIC_EXECUTION]: The skill's primary architecture involves the generation of a p5.js-based web page (
figure.html) that is subsequently executed in a browser environment. This runtime execution of dynamically generated code is used to produce the visual figures and SVG exports. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest an external
[composition source]—a URL or local path to an existing figure—which is then processed by a vision-capable reviewer. This ingestion of untrusted visual data represents an attack surface where malicious patterns or instructions embedded within the source image could influence the agent's iterative design process. - Ingestion points:
[composition source]provided in$ARGUMENTSand processed in Phase 4. - Boundary markers: The instructions tell the reviewer to 'Judge only from this image,' but there are no technical sanitization steps for the visual input itself.
- Capability inventory: Uses
Bashto run browsers,Write/Editto modify code, andWebFetchto retrieve data. - Sanitization: No visual sanitization or instruction filtering is applied to the input source image.
Audit Metadata