design-md
Pass
Audited by Gen Agent Trust Hub on Mar 4, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection. It retrieves and processes external HTML source code and design metadata from projects. Malicious instructions embedded within the target HTML could influence the agent's behavior during the analysis and synthesis phase.
- Ingestion points: Technical assets fetched via
web_fetchfromhtmlCode.downloadUrlandscreenshot.downloadUrlinSKILL.md. - Boundary markers: No specific delimiters or "ignore instructions" warnings are used when processing the external content.
- Capability inventory: File system
Writeaccess,web_fetchfor network operations, and access tostitchMCP tools. - Sanitization: No evidence of sanitization or filtering of the fetched HTML content before it is processed by the model.
- [EXTERNAL_DOWNLOADS]: Fetches project assets (HTML and screenshots) from the Stitch platform, which is a well-known service. It also references official documentation from
stitch.withgoogle.com.
Audit Metadata