design-to-code
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input from external URLs and screenshots to extract design context, which is then used to generate and adapt local source code.
- Ingestion points: Stage 1 (Extract) accepts an untrusted screenshot-path, natural language description, or external URL in SKILL.md.
- Boundary markers: The instructions do not define boundary markers or explicit safety directives to ignore potential commands embedded within the extracted design context or fetched web content.
- Capability inventory: The skill is granted
Write,Edit, andBashpermissions, allowing it to modify the project's source code and execute commands in the terminal. - Sanitization: There is no logic provided to sanitize or validate the design context extracted from external mockups before it influences code generation in Stage 3.
- [COMMAND_EXECUTION]: The skill requests and utilizes the
Bashtool to perform filesystem operations (Grep/Glob) and run Storybook tests as part of its self-healing verification loop.
Audit Metadata