redesign-existing-projects
Pass
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill establishes a workflow to scan and read codebase files to diagnose design weaknesses. This ingestion of untrusted external content represents a surface for indirect prompt injection.
- Ingestion points: Reads files from the user's project codebase as part of the scan and diagnosis steps.
- Boundary markers: The instructions lack explicit boundary markers or warnings to the agent to ignore instructions embedded within the audited code.
- Capability inventory: The agent is directed to read files and perform modifications to the project's styling and semantic structure.
- Sanitization: No specific sanitization or verification steps are provided for the content read from the external codebase.
- [EXTERNAL_DOWNLOADS]: The skill recommends using
https://picsum.photosas a fallback source for high-quality background imagery and placeholder assets. This is a well-known, standard service for development and design contexts and is documented neutrally as it does not pose a security risk.
Audit Metadata