redesign-existing-projects
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to scan and audit existing codebases to identify design flaws and apply fixes. This ingestion of untrusted source code provides a surface for indirect prompt injection where malicious instructions could be embedded in the codebase to influence the agent's actions during the modification phase.
- Ingestion points: Project source files including CSS, HTML, and Javascript (SKILL.md, Step 1).
- Boundary markers: No delimiters or instructions to ignore embedded directives are provided for the scanning phase.
- Capability inventory: The agent performs file system read and write operations across the project directory (SKILL.md, Step 3).
- Sanitization: There are no instructions to sanitize or validate the content of the files before processing.
Audit Metadata