aep-design

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill operates by analyzing project context and codebase patterns to generate designs, which introduces a surface for indirect prompt injection.\n
  • Ingestion points: Untrusted data enters the agent's context through user-provided feature ideas, the product-context.yaml file, and by investigating the existing codebase for patterns.\n
  • Capability inventory: The skill possesses capabilities to write files to the repository, commit changes via git, and invoke other automated tools such as /opsx:explore and /opsx:propose.\n
  • Boundary markers: The instructions do not define clear boundaries or provide explicit instructions for the agent to ignore or isolate instructions that might be embedded within the ingested codebase files.\n
  • Sanitization: There is no evidence of specific sanitization, validation, or escaping of the codebase content or user inputs before they are interpolated into the design generation prompts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 11:02 AM
Security Audit — agent-trust-hub — aep-design