agent-designer
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill includes several Python scripts (
agent_evaluator.py,agent_planner.py,tool_schema_generator.py) that ingest data from external JSON files. This creates a potential vector where untrusted data (such as execution logs or requirement descriptions) could influence the agent's behavior during analysis or design phases. - Ingestion points:
agent_evaluator.py(Line 485),agent_planner.py(Line 448), andtool_schema_generator.py(Line 434) read and process data from user-supplied JSON files usingjson.load(). - Boundary markers: The scripts lack explicit boundary markers or instructions to the LLM to ignore potentially adversarial directives embedded within natural language fields like
task_descriptionorerror_message. - Capability inventory: The toolkit allows agents to write generated architectures, diagrams, and evaluation reports to the local filesystem using configurable output paths.
- Sanitization: While the scripts perform basic structural validation of JSON data, they do not sanitize natural language content that is subsequently processed by the agent.
Audit Metadata