studio-design-magic-moment
Pass
Audited by Gen Agent Trust Hub on Aug 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from user-controlled files, creating a surface for indirect prompt injection attacks where malicious instructions could be embedded in the product documentation.
- Ingestion points: The skill reads
docs/PRODUCT.mdandproductos/design/1-Product-Identity.mdto extract product details and brand character. - Boundary markers: The instructions do not define specific delimiters or guardrails to prevent the agent from executing instructions potentially hidden within the user-provided markdown files.
- Capability inventory: The skill is authorized to read local files and perform file writes to
productos/design/2-Magic-Moment.md. - Sanitization: There is no evidence of sanitization or content validation for the ingested files before they are processed by the agent.
Audit Metadata