redesign-existing-projects

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill establishes a workflow to scan and read codebase files to diagnose design weaknesses. This ingestion of untrusted external content represents a surface for indirect prompt injection.
  • Ingestion points: Reads files from the user's project codebase as part of the scan and diagnosis steps.
  • Boundary markers: The instructions lack explicit boundary markers or warnings to the agent to ignore instructions embedded within the audited code.
  • Capability inventory: The agent is directed to read files and perform modifications to the project's styling and semantic structure.
  • Sanitization: No specific sanitization or verification steps are provided for the content read from the external codebase.
  • [EXTERNAL_DOWNLOADS]: The skill recommends using https://picsum.photos as a fallback source for high-quality background imagery and placeholder assets. This is a well-known, standard service for development and design contexts and is documented neutrally as it does not pose a security risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 05:26 AM
Security Audit — agent-trust-hub — redesign-existing-projects