bolder
Pass
Audited by Gen Agent Trust Hub on Jul 31, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill instructs the agent to gather context from the codebase and current thread, creating an attack surface for indirect prompt injection where malicious instructions could be embedded in the design context.
- Ingestion points: Reads target audience, use-cases, and brand personality from the codebase and thread.
- Boundary markers: The instructions do not define delimiters or specific markers to distinguish external context from system instructions.
- Capability inventory: The skill is used to modify frontend design, implying code-modification capabilities.
- Sanitization: There is no instruction to sanitize or filter the content gathered from the codebase or conversation history before it is used to influence agent behavior.
Audit Metadata