design-dna
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests user-provided design references to generate new agent instructions (
PROMPT.md) and configuration files (dna.json). This workflow introduces a surface where malicious content within the analyzed design could potentially influence the agent's codification logic, although the mandated seven-step forensic process provides a structured defense. - [COMMAND_EXECUTION]: The skill utilizes local Python scripts (
emit.pyandcheck.py) for project scaffolding, validation, and automated testing. It also references the vendor-specific tool@ericrisco/rscvianpxto diagnose the project's starting point and identity records. - [DYNAMIC_EXECUTION]: The
emit.pyscript programmatically modifies file permissions usingos.chmodto make generated test scripts executable. This is a standard functional operation for creating a runnable development harness.
Audit Metadata