redesign-existing-projects
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Suggests using https://picsum.photos for placeholder images when original assets are unavailable. This is a well-known and reliable service for design development.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted code from external projects and possesses the capability to modify that code, creating a potential surface for indirect prompt injection.
- Ingestion points: The skill reads the project framework, styling implementation, and codebase structure during the initial scan in SKILL.md.
- Boundary markers: No specific delimiters or instructions are used to isolate project code from the agent's internal logic.
- Capability inventory: The agent can write modifications to project files, including CSS and component templates, based on its analysis.
- Sanitization: There is no explicit validation or sanitization logic for the ingested codebase content before it is processed.
Audit Metadata