design-mobile-apps

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes and saves HTML and JSON data fetched from external API endpoints (e.g., https://sleek.design/api/v1/projects/:id/components/:componentId). This content is untrusted and could potentially contain malicious instructions designed to influence the agent's behavior during the implementation phase.
  • Ingestion points: API responses from sleek.design containing JSON data and HTML component code, as described in SKILL.md under the 'Components' and 'Implementing Designs' sections.
  • Boundary markers: None. The instructions do not specify any delimiters or warnings to ignore instructions embedded within the fetched HTML or JSON data.
  • Capability inventory: The skill utilizes shell commands (curl) to fetch data and has the ability to write files (HTML documents, JSON, and screenshots) to the local filesystem.
  • Sanitization: No sanitization, escaping, or validation of the fetched external content is mentioned before it is processed or written to disk.
  • [EXTERNAL_DOWNLOADS]: The skill requires downloading content from external sources to function, specifically from https://sleek.design and https://api.iconify.design.
  • Evidence: Instructions to fetch component code, screenshots, and SVG icons from these domains are present throughout SKILL.md.
  • [COMMAND_EXECUTION]: The skill explicitly instructs the agent to use shell commands to interact with the API and manage files.
  • Evidence: Use of curl -o run.json to save API responses and piping response bodies into files to avoid terminal output issues.
  • [METADATA_POISONING]: There is a discrepancy between the skill's declared permissions and its operational requirements.
  • Evidence: The frontmatter allowed-hosts field only lists https://sleek.design, yet the instructions in the 'Icons' section explicitly require the agent to perform GET requests to https://api.iconify.design to retrieve SVGs.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 10:19 AM
Security Audit — agent-trust-hub — design-mobile-apps