design-eng

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted user input, such as UI requests and code snippets, to determine which sibling skill should handle the task. This routing mechanism constitutes an indirect prompt injection surface.
  • Ingestion points: User prompts describing frontend issues and UI code blocks (SKILL.md).
  • Boundary markers: The skill does not define specific delimiters or instructions to separate user data from routing instructions.
  • Capability inventory: The skill's primary function is routing; it does not execute system commands, write files, or initiate network connections.
  • Sanitization: There is no evidence of input validation or sanitization to prevent malicious instructions within the UI requests from affecting agent behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 08:57 AM
Security Audit — agent-trust-hub — design-eng