aep-design-lens

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the analysis of untrusted external data, including live URLs and product specifications, which creates an inherent surface for indirect prompt injection attacks where malicious instructions could be embedded in the content being audited.\n
  • Ingestion points: As described in SKILL.md and references/method-and-templates.md, the agent is instructed to characterize and audit external products, running UIs, and specifications, often utilizing the agent browser for evidence gathering.\n
  • Boundary markers: The instructions do not prescribe the use of delimiters or protective phrasing (e.g., 'treat following content as data-only') when the agent processes these external inputs.\n
  • Capability inventory: The agent possesses capabilities to access the network via browser tools and write output to the local file system in the docs/design-review/ directory.\n
  • Sanitization: There are no requirements defined for the agent to sanitize, filter, or validate external content before it is incorporated into the design evaluation logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 11:02 AM
Security Audit — agent-trust-hub — aep-design-lens