hallmark— agent skill

hallmark — independently scanned and version-tracked by SaferSkills.

by mouadja02·Agent Skill·github.com/mouadja02/skills

Is hallmark safe to install?

SaferSkills independently audited hallmark (Agent Skill) and scored it 71/100 (yellow). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 7 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.

Score
71/100
●●●●●●●○○○
↑ +0 since first scan (71 → 71)Re-scan~30s
Latest scan
ScannedJun 28, 2026 · 25d ago
Scans run1 over 90 days
Detectors55 checks · 5 categories
Findings7 warnings · 0 high
EngineSaferSkills 2b638c6
View methodology →
SaferSkills installs
This week0
This month0
All time0
CategoryWeightCategory scoreContribution
Securityprompt, exec, net, exfil, eval
35%
16
5.6 pts
Supply chainhash, typosquat, maintainer, lockfile
20%
100
20.0 pts
Maintenancestaleness, pinning, CI
15%
100
15.0 pts
TransparencySKILL.md, perms, README
15%
100
15.0 pts
Communityinstalls, verify, response
15%
100
15.0 pts

Findings & checks · 7 flagged

Securityscore 16 · 7 findings
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · skills/design-and-ui/hallmark/SKILL.md×3
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptskills/design-and-ui/hallmark/SKILL.md· markdown
218> *Or say **"go ahead"** and I'll infer from the brief — I'll tell you what I picked.*
219 
220Send the prompt **once**, in one message. Bold the three labels (Audience / Use case / Tone)
… (108 chars elided on L220)
221 
222**One exception** where the gate is silent:
Occurrences
3 occurrences · first at L220, also L248, L335
Show all 3 locations
Line
File
L220
skills/design-and-ui/hallmark/SKILL.md
L248
skills/design-and-ui/hallmark/SKILL.md
L335
skills/design-and-ui/hallmark/SKILL.md
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha256ce5204b52388d24frubric 365aacaView on GitHub
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · skills/design-and-ui/hallmark/docs/recipes.md
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptskills/design-and-ui/hallmark/docs/recipes.md· markdown
119**Prompt:**
120 
121> *"Personal site for Anya — software architect in Lisbon. Don't ask, just figure it out."*
122 
123**Inferred trio** (the user opted out): audience = engineering hiring managers · use = read
… (57 chars elided on L123)
Occurrences
1 occurrence · at L121
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha25615dae9807bd892c6rubric 365aacaView on GitHub
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · skills/design-and-ui/hallmark/references/custom-theme.md
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptskills/design-and-ui/hallmark/references/custom-theme.md· markdown
37> *Optional second input: an anchor colour — hex, OKLCH, or a name like 'terracotta', 'sea-b
… (82 chars elided on L37)
38 
39**Do not ask anything else.** Audience / use / tone (Step 1) plus the brand vibe is already
… (108 chars elided on L39)
40 
41If the user gives just two or three words ("sun-drenched"), proceed; the recipe below extrac
… (92 chars elided on L41)
Occurrences
1 occurrence · at L39
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha25668b030f55bcd484arubric 365aacaView on GitHub
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · skills/design-and-ui/hallmark/site/_tests/06-anya-portfolio/brief.md
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptskills/design-and-ui/hallmark/site/_tests/06-anya-portfolio/brief.md· markdown
3## The prompt (verbatim, same as v1)
4 
5> "I'm Anya, a software architect. Build me a one-pager. Don't ask me questions, just figure
… (9 chars elided on L5)
6 
7## Step 0 · Pre-flight
Occurrences
1 occurrence · at L5
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha25615dae9807bd892c6rubric 365aacaView on GitHub
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · skills/design-and-ui/hallmark/site/_tests/README.md
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptskills/design-and-ui/hallmark/site/_tests/README.md· markdown
12| 04 | Manifesto for an environmental studio `Meridian` | Partial ("declarative, no flashy s
… (103 chars elided on L12)
13| 05 | SaaS observability tool `Tracejam` | Full (SREs / try-or-talk-to-sales / technical) |
… (58 chars elided on L13)
14| 06 | Personal one-pager for `Anya` (software architect) | **Skipped** ("don't ask, just fi
… (60 chars elided on L14)
15| 07 | SOC2 / ISO27001 compliance SaaS `Foundry` | Full (founders + CTOs / try-or-talk-to-sa
… (108 chars elided on L15)
16| 08 | Cohort-based courses platform `Cohort` | Full (educators / run-courses / warm-salon-r
… (101 chars elided on L16)
Occurrences
1 occurrence · at L14
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha256ce5204b52388d24frubric 365aacaView on GitHub
Supply chainscore 100 · 0 findings
All supply chain checks passedNo findings in this category for the latest scan.pass
Maintenancescore 100 · 0 findings
All maintenance checks passedNo findings in this category for the latest scan.pass
Transparencyscore 100 · 0 findings
All transparency checks passedNo findings in this category for the latest scan.pass
Communityscore 100 · 0 findings
All community checks passedNo findings in this category for the latest scan.pass
Vendor response · right of reply
Are you the maintainer? Submit a response →

Audit the pieces. Scan the whole. Decide.

~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.