system-design

Pass

Audited by Gen Agent Trust Hub on Aug 22, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill operates as a CTO deputy, guiding users through Socratic questioning to design software systems. All content consists of instructional markdown and code templates for TypeScript project structures.
  • [SAFE]: No prompt injection or behavior override patterns were found. The skill maintains a consistent role-play for its stated architectural purpose.
  • [SAFE]: No data exposure or exfiltration risks detected. Code templates use standard practices like http://localhost for testing and process.env.PORT for configuration, which do not constitute credential exposure or unauthorized network access.
  • [SAFE]: No obfuscation techniques, hidden URLs, or malicious persistence mechanisms were identified in the source files.
  • [SAFE]: The skill does not perform remote code execution or package installation. It provides documentation on how a developer might structure their own code, but the agent itself does not execute these templates on the host system.
  • [SAFE]: Indirect Prompt Injection risk is minimal. While the skill processes user descriptions of systems, it employs boundary-strengthening techniques by reflecting back understanding and requiring explicit confirmation at every phase (Discovery, Modeling, Boundaries).
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 22, 2026, 12:42 PM
Security Audit — agent-trust-hub — system-design