meridian-design

Pass

Audited by Gen Agent Trust Hub on Apr 16, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection through its design analysis workflow.
  • Ingestion points: The skill reads project files (CSS, HTML, etc.) during the /m-scan process to build a .meridian.json profile.
  • Boundary markers: There are no instructions defining delimiters or warnings to ignore malicious instructions that might be embedded in the analyzed code comments or content.
  • Capability inventory: The agent is instructed to write CSS and provide design recommendations based on the generated profile.
  • Sanitization: No explicit sanitization or validation logic is provided to filter the content of ingested files before they are used to guide the agent's behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 16, 2026, 08:23 AM