design-system

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_CONTEXT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from several project files to inform its design logic and specialist agent prompts.
  • Ingestion points: design/gdd/game-concept.md, design/gdd/systems-index.md, design/registry/entities.yaml, docs/consistency-failures.md, dependency GDD files, project.yaml, and architectural decision records (docs/architecture/adr-*.md).
  • Boundary markers: Absent. There are no explicit delimiters or instructions to the LLM to disregard potentially malicious content within these files.
  • Capability inventory: The skill has write access to the filesystem (Write, Edit) and the ability to spawn other agents (Agent) and execute specific shell commands (Bash).
  • Sanitization: Absent. Content from ingested files is processed and interpolated into prompts without visible sanitization or validation.
  • [DYNAMIC_CONTEXT_INJECTION]: The skill utilizes the ! command syntax to execute a shell script at load time to populate its configuration.
  • Evidence: The line !`bash "${CLAUDE_SKILL_DIR}/../../hooks/yaml-helper.sh" resolve_config --keys review_mode,automation,workflow,docs.density,system_overrides` triggers an automatic execution of a local helper script to resolve settings.
  • [COMMAND_EXECUTION]: The skill uses the Bash tool to interact with project-specific tooling for configuration management. While the execution is restricted via allowed-tools to a specific helper script and the resolve_config subcommand, it performs active shell command execution based on project paths.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 04:23 PM
Security Audit — agent-trust-hub — design-system