ux-design

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEPROMPT_INJECTIONDYNAMIC_CONTEXT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The SKILL.md file contains a self-assigned completion status "Verdict: COMPLETE", which is a self-referential attempt to influence the agent's evaluation process.
  • [DYNAMIC_CONTEXT_INJECTION]: The skill utilizes the load-time execution syntax "!" to run a local bash script ("yaml-helper.sh") for configuration resolution, which executes shell commands outside the immediate skill directory.
  • [INDIRECT_PROMPT_INJECTION]: The skill aggregates content from project files like GDDs and player journeys, creating a potential injection surface. 1. Ingestion points: design/gdd/*.md, design/player-journey.md, design/art/art-bible.md, and project.yaml. 2. Boundary markers: Absent. 3. Capability inventory: Write, Edit, and Bash tools across multiple files. 4. Sanitization: Absent.
  • [PROMPT_INJECTION]: Instructions for autonomous mode specify that the agent can "log and proceed" instead of requesting user approval, which reduces human-in-the-loop oversight during file modification tasks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 05:00 PM
Security Audit — agent-trust-hub — ux-design