skills/corvalis-llc/crow-stack/design/Gen Agent Trust Hub

design

Pass

Audited by Gen Agent Trust Hub on Jun 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [SAFE]: No malicious patterns or security risks were identified. The skill functions as a design orchestrator using local project data.
  • [COMMAND_EXECUTION]: The orchestrator dispatches subagents with permission to use file system tools such as Read, Write, Grep, and Edit. These capabilities are restricted to component management and design auditing within the current project environment.
  • [EXTERNAL_DOWNLOADS]: The skill documentation references several well-known and established design services including Apple Human Interface Guidelines, Vercel Geist, Stripe, and GitHub Primer for pattern inspiration. All referenced domains are well-known technology providers.
  • [PROMPT_INJECTION]: The instructions contain directives for silent bootstrapping and automated workflow execution ('No Questions'). These are operational constraints to ensure the design system is correctly loaded before task execution and do not constitute a bypass of agent safety filters.
  • [PROMPT_INJECTION]: The skill processes project source code (.svelte files) which acts as an indirect prompt injection surface.
  • Ingestion points: The Auditor and Pattern Matcher agents scan files in src/lib/components/ and src/routes/.
  • Boundary markers: No explicit delimiters or instructions to ignore embedded content were found in the agent prompts.
  • Capability inventory: The Builder and Migrator agents are equipped with Write and Edit tools to modify project source code.
  • Sanitization: No content validation or escaping mechanisms for the analyzed code were identified.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 19, 2026, 05:36 AM
Security Audit — agent-trust-hub — design