design-prd

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the web using the firecrawl_scrape tool to research UX patterns and competitive features. This data is incorporated into the agent's context without explicit boundary markers or instructions to disregard potential malicious directives embedded in the scraped content.\n
  • Ingestion points: External web content fetched via firecrawl:firecrawl_scrape and user-provided feature descriptions in Step 2.\n
  • Boundary markers: Absent; the instructions do not specify how to delimit or sanitize external content to prevent the agent from following instructions contained within that content.\n
  • Capability inventory: The agent possesses capabilities to read local source code and configuration files (Glob, Grep), execute database queries (supabase:execute_sql), perform web searches (firecrawl), and write files to the local filesystem (Step 6: Save).\n
  • Sanitization: There is no evidence of filtering or validation logic for the external content before it is processed by the model.\n- [COMMAND_EXECUTION]: The skill leverages filesystem search tools to identify the tech stack, features, and data models of the current project. This involves scanning directories for route files, migration scripts, and documentation. While these actions are aligned with the skill's purpose, they require broad read access to the local development environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 05:56 AM
Security Audit — agent-trust-hub — design-prd