design-audit
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze untrusted data from URLs and code repositories, which serves as an ingestion point for potential indirect prompt injections.
- Ingestion points:
SKILL.mdworkflow instructions for URLs and repository apps. - Boundary markers: None defined in instructions to delimit external content.
- Capability inventory: Access to file system and instruction to run applications.
- Sanitization: No mention of content sanitization.
- [DYNAMIC_EXECUTION]: The workflow instructions in
SKILL.mdencourage the execution of the target application code ('run the app when feasible') to support the design audit process.
Audit Metadata