design-engineer

Pass

Audited by Gen Agent Trust Hub on Aug 12, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill workflow involves reading external project files which can act as a vector for indirect prompt injection attacks.- Ingestion points: The agent is instructed in SKILL.md to read project design guidance, including AGENTS.md, design-system documents, and token files, and to inspect the target UI source code.- Boundary markers: The instructions lack specific boundary markers or 'ignore' directives for content processed from these project files.- Capability inventory: The agent has the authority to modify the project's codebase during implementation and execute shell commands for linting and testing.- Sanitization: There is no evidence of content sanitization or validation logic for the ingested files before they are processed by the LLM.- [COMMAND_EXECUTION]: The skill directs the agent to execute local development tools as part of its verification process.- Evidence: The 'Verify' section in SKILL.md requires the agent to 'Run the project’s targeted lint/typecheck/tests for touched files'. This is a standard development capability but constitutes a command execution surface.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 12, 2026, 12:30 PM
Security Audit — agent-trust-hub — design-engineer