design-to-code

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input from external URLs and screenshots to extract design context, which is then used to generate and adapt local source code.
  • Ingestion points: Stage 1 (Extract) accepts an untrusted screenshot-path, natural language description, or external URL in SKILL.md.
  • Boundary markers: The instructions do not define boundary markers or explicit safety directives to ignore potential commands embedded within the extracted design context or fetched web content.
  • Capability inventory: The skill is granted Write, Edit, and Bash permissions, allowing it to modify the project's source code and execute commands in the terminal.
  • Sanitization: There is no logic provided to sanitize or validate the design context extracted from external mockups before it influences code generation in Stage 3.
  • [COMMAND_EXECUTION]: The skill requests and utilizes the Bash tool to perform filesystem operations (Grep/Glob) and run Storybook tests as part of its self-healing verification loop.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 03:08 PM
Security Audit — agent-trust-hub — design-to-code