design-bridge

Pass

Audited by Gen Agent Trust Hub on Jun 28, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill processes external markdown files, creating a surface for indirect prompt injection.
  • Ingestion points: Fetches DESIGN.md files from external sources like the 'VoltAgent/awesome-design-md' collection.
  • Boundary markers: No specific delimiters or security warnings are used to distinguish design data from instructions.
  • Capability inventory: The skill is configured with 'workspace-write' access to save synthesized files.
  • Sanitization: Input content is not sanitized or validated before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 28, 2026, 11:06 AM
Security Audit — agent-trust-hub — design-bridge