design-exploration
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data by reading existing project files and configuration to inform its design variants.
- Ingestion points: Phase 1 (Research) instructs the agent to read existing code, globals.css, tailwind configuration, and study existing component patterns and assets.
- Boundary markers: The skill lacks explicit instructions or delimiters to ignore potential instructions embedded within the CSS comments, component code, or asset metadata.
- Capability inventory: The skill has significant capabilities including reading multiple project files and overwriting existing files with new implementations in Phase 3.
- Sanitization: There is no mention of sanitizing or filtering instructions that might be contained within the code files it is tasked to study.
Audit Metadata