aep-design
Pass
Audited by Gen Agent Trust Hub on Sep 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill operates by analyzing project context and codebase patterns to generate designs, which introduces a surface for indirect prompt injection.\n
- Ingestion points: Untrusted data enters the agent's context through user-provided feature ideas, the
product-context.yamlfile, and by investigating the existing codebase for patterns.\n - Capability inventory: The skill possesses capabilities to write files to the repository, commit changes via
git, and invoke other automated tools such as/opsx:exploreand/opsx:propose.\n - Boundary markers: The instructions do not define clear boundaries or provide explicit instructions for the agent to ignore or isolate instructions that might be embedded within the ingested codebase files.\n
- Sanitization: There is no evidence of specific sanitization, validation, or escaping of the codebase content or user inputs before they are interpolated into the design generation prompts.
Audit Metadata