NYC

vaporwave-glassomorphic-ui-designer

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • Data Exposure & Exfiltration (LOW): The skill utilizes tools such as mcp__firecrawl__firecrawl_search and WebFetch to perform network operations to non-whitelisted domains for design research.
  • Indirect Prompt Injection (LOW): The skill possesses a vulnerability surface for indirect prompt injection through external data ingestion combined with local file modification capabilities. 1. Ingestion points: mcp__firecrawl__firecrawl_search and WebFetch tools listed in SKILL.md. 2. Boundary markers: No explicit delimiters or warnings to ignore embedded instructions are present in the skill definition. 3. Capability inventory: The skill is granted Write and Edit permissions for modifying local files. 4. Sanitization: No sanitization or validation logic for external content is defined.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 05:41 PM