studio-design-prompt-generator
Pass
Audited by Gen Agent Trust Hub on Aug 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests content from several user-editable files, including
docs/PRODUCT.md,productos/design/1-Product-Identity.md, anddocs/DESIGN.md. This data is then interpolated into design prompts that are written toproductos/design/Design-Prompts.md. Although the skill uses triple-backtick blocks for output delimitation, it does not include instructions for sanitizing the input data, which could allow maliciously crafted content in the source files to affect the generated output. The impact is low because the skill is restricted to local file operations and has no network or shell execution capabilities.
Audit Metadata