unboundx-design
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill consists exclusively of brand documentation and static SVG templates. No executable code, scripts, or network-enabled tools are included, precluding common attack vectors like remote code execution or data exfiltration.
- [INDIRECT_PROMPT_INJECTION]: The skill processes user input by interpolating values into SVG templates, creating a potential injection surface. This is evaluated as safe because the skill has no dangerous capabilities (no network access, file writing, or command execution) that could be exploited. 1. Ingestion points: User-provided strings for placeholders like {name} and {event_title} in 'references/scenario-playbooks.md'. 2. Boundary markers: Absent within the SVG template strings. 3. Capability inventory: None. 4. Sanitization: Not explicitly defined in the provided assets.
Audit Metadata