dev-design

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: Instructions trigger the execution of npx ai-devkit commands to perform linting and design validation as part of the phase contract.
  • [EXTERNAL_DOWNLOADS]: The skill uses npx with the @latest tag, which fetches the most recent version of the ai-devkit package from the public NPM registry during execution.
  • [REMOTE_CODE_EXECUTION]: Running the ai-devkit package via npx involves executing code retrieved from a remote registry at runtime.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data from requirements and design documents, creating a surface where instructions embedded in those documents could influence the agent.
  • Ingestion points: Processes content from requirements and design docs located in paths like docs/ai as specified in SKILL.md.
  • Boundary markers: The skill does not define specific delimiters or instructions to isolate external document content from the agent's primary directives.
  • Capability inventory: Includes the ability to execute shell commands and modify local project files.
  • Sanitization: No explicit sanitization or validation of the external document content is performed before analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 02:02 AM
Security Audit — agent-trust-hub — dev-design