design-high-level

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input from external requirement documents to generate high-level design sections. If a requirements document contains malicious instructions, the agent might follow them during the generation process. However, the skill's lack of high-privilege capabilities restricts the potential impact.
  • Ingestion points: Docs/requirements/ (referenced in SKILL.md)
  • Boundary markers: Absent; the skill does not define specific delimiters for external content.
  • Capability inventory: File system write access to Docs/designs/ and Docs/In-Progress/ for saving HLD documents.
  • Sanitization: Absent; no explicit instructions are provided to the agent to sanitize or ignore instructions embedded within the source requirements files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 11:21 AM
Security Audit — agent-trust-hub — design-high-level