design-catalog

Pass

Audited by Gen Agent Trust Hub on Feb 23, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes python -m http.server 8888 & to host a local preview of the generated designs. This is a standard utility command for development workflows.- [EXTERNAL_DOWNLOADS]: The skill utilizes Gemini and Chrome MCP tools to retrieve external web data and screenshots for design analysis. These operations are performed through standard integrated tools.- [PROMPT_INJECTION]: The skill incorporates external data from URLs and research results into agent prompts. This presents a surface for indirect prompt injection (Category 8). Evidence Chain: 1. Ingestion points: $1 argument (route/URL), Gemini research output, and Chrome screenshots. 2. Boundary markers: Absent. 3. Capability inventory: Filesystem writes, Python HTTP server execution, and MCP agent spawning. 4. Sanitization: Not explicitly defined in the instructions. While the surface exists, no malicious patterns are present in the static skill definition.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 23, 2026, 09:43 PM