design-brief
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements a secure-by-design approach by requiring the agent to map all user inputs to a strict 'closed vocabulary' of symbolic values defined in Section 2.1. Any unrecognized values must trigger a clarification prompt rather than being processed, which serves as an effective safeguard against prompt injection and unexpected behavior.
- [DATA_EXPOSURE]: The skill requests the
file_writecapability, which is used solely to generate aDESIGN.mdspecification and abrief-preview.htmlfile within the working directory. No access to sensitive system paths (e.g., .ssh, .aws) or hardcoded credentials was identified. - [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied design briefs, creating a potential attack surface. However, this risk is mitigated by the following evidence chain: 1) Ingestion point is the
briefinput string inSKILL.md. 2) Boundary markers are established via the strict symbolic-to-token resolution table. 3) Capabilities are limited to local file writing. 4) Sanitization is performed through the mandatory mapping logic that rejects input not matching the predefined design system vocabulary.
Audit Metadata