foundry
Pass
Audited by Gen Agent Trust Hub on Aug 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest data from local project files, such as brand documentation, CSS files, and READMEs, using
findandripgrep. This identifies a surface where external content within the project could potentially influence the agent's output. - [COMMAND_EXECUTION]: The skill utilizes common shell utilities, including
ls,find, andrg, to survey the project's directory structure for existing design assets and configuration. These commands are standard for developer productivity tools and are scoped to the project environment.
Audit Metadata