unboundx-design

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill consists exclusively of brand documentation and static SVG templates. No executable code, scripts, or network-enabled tools are included, precluding common attack vectors like remote code execution or data exfiltration.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user input by interpolating values into SVG templates, creating a potential injection surface. This is evaluated as safe because the skill has no dangerous capabilities (no network access, file writing, or command execution) that could be exploited. 1. Ingestion points: User-provided strings for placeholders like {name} and {event_title} in 'references/scenario-playbooks.md'. 2. Boundary markers: Absent within the SVG template strings. 3. Capability inventory: None. 4. Sanitization: Not explicitly defined in the provided assets.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 09:54 PM
Security Audit — agent-trust-hub — unboundx-design