codebase-design
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill implements a multi-agent design workflow where user-supplied problem descriptions and constraints are used to brief sub-agents. This creates a potential surface for indirect prompt injection where malicious input could influence the sub-agents, although the intent is purely for architectural design brainstorming.
- Ingestion points: User-provided problem space descriptions and technical briefs used to prompt sub-agents in
DESIGN-IT-TWICE.md. - Boundary markers: The instructions do not explicitly specify delimiters or isolation warnings for the user-supplied content passed to the sub-agents.
- Capability inventory: The skill utilizes the platform's
Agenttool to spawn and coordinate sub-agents. - Sanitization: There is no explicit sanitization or validation of the user-provided context before it is interpolated into sub-agent prompts.
Audit Metadata