dev-design
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: Instructions trigger the execution of
npx ai-devkitcommands to perform linting and design validation as part of the phase contract. - [EXTERNAL_DOWNLOADS]: The skill uses
npxwith the@latesttag, which fetches the most recent version of theai-devkitpackage from the public NPM registry during execution. - [REMOTE_CODE_EXECUTION]: Running the
ai-devkitpackage vianpxinvolves executing code retrieved from a remote registry at runtime. - [INDIRECT_PROMPT_INJECTION]: The skill processes external data from requirements and design documents, creating a surface where instructions embedded in those documents could influence the agent.
- Ingestion points: Processes content from requirements and design docs located in paths like
docs/aias specified inSKILL.md. - Boundary markers: The skill does not define specific delimiters or instructions to isolate external document content from the agent's primary directives.
- Capability inventory: Includes the ability to execute shell commands and modify local project files.
- Sanitization: No explicit sanitization or validation of the external document content is performed before analysis.
Audit Metadata