gstack-design-html

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests external design descriptions and DESIGN.md files to generate code, which could contain instructions designed to manipulate the agent's output or behavior.
  • Ingestion points: The agent is instructed to read DESIGN.md and user-provided mockup descriptions in Step 0.
  • Capability inventory: The skill utilizes Bash, Write, and Edit tools to create and modify files and detect the project environment.
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to ignore instructions embedded within the ingested design data.
  • Sanitization: The skill does not specify any sanitization or validation logic for the content processed from external design sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 05:56 PM
Security Audit — agent-trust-hub — gstack-design-html