static-visual-design
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external, untrusted data to guide image generation, creating a surface where embedded instructions could potentially influence agent behavior. Ingestion points: The skill ingests data from user-attached files, files in the workspace recovered via list_all_user_files, and external content retrieved from official brand websites using web tools. Boundary markers: The instructions rely on precise art direction prompts and design specifications, but do not specify the use of explicit delimiters (like 'ignore embedded instructions') when processing external files or web content. Capability inventory: The skill utilizes image generation and editing tools (generate_image, edit_image) and visual analysis capabilities (understand_media). Sanitization: The skill contains robust inspection protocols, mandating that the agent verify all text, claims, and identity marks (logos/QR codes) using vision tools to ensure they are authentic and correctly rendered, which helps mitigate the risk of malicious or incorrect content being finalized.
Audit Metadata