redesign-existing-projects

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill requires the agent to 'Scan — Read the codebase' to identify styling and design patterns. This processing of untrusted external data (project files) creates an attack surface where malicious instructions hidden in code comments or strings could potentially influence the agent's actions. The skill lacks explicit boundary markers or sanitization instructions for handling this external content. The listed tools, such as 'cursor' and 'claude', possess capabilities to modify files and write to the filesystem, which could be leveraged if an injection is successful.
  • [EXTERNAL_DOWNLOADS]: The design audit recommends the use of 'https://picsum.photos/' as a source for placeholder imagery when real assets are unavailable. This is a well-known and established service for UI development and does not represent a security risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 08:05 PM
Security Audit — agent-trust-hub — redesign-existing-projects