design-system
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_CONTEXT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from several project files to inform its design logic and specialist agent prompts.
- Ingestion points:
design/gdd/game-concept.md,design/gdd/systems-index.md,design/registry/entities.yaml,docs/consistency-failures.md, dependency GDD files,project.yaml, and architectural decision records (docs/architecture/adr-*.md). - Boundary markers: Absent. There are no explicit delimiters or instructions to the LLM to disregard potentially malicious content within these files.
- Capability inventory: The skill has write access to the filesystem (
Write,Edit) and the ability to spawn other agents (Agent) and execute specific shell commands (Bash). - Sanitization: Absent. Content from ingested files is processed and interpolated into prompts without visible sanitization or validation.
- [DYNAMIC_CONTEXT_INJECTION]: The skill utilizes the
!command syntax to execute a shell script at load time to populate its configuration. - Evidence: The line
!`bash "${CLAUDE_SKILL_DIR}/../../hooks/yaml-helper.sh" resolve_config --keys review_mode,automation,workflow,docs.density,system_overrides`triggers an automatic execution of a local helper script to resolve settings. - [COMMAND_EXECUTION]: The skill uses the
Bashtool to interact with project-specific tooling for configuration management. While the execution is restricted viaallowed-toolsto a specific helper script and theresolve_configsubcommand, it performs active shell command execution based on project paths.
Audit Metadata