dpai-craft
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill interacts with external interface source code and project design rules as part of its primary workflow.
- Ingestion points: The workflow in
SKILL.mddescribes reading project interface rules, design tokens, and source code for components and screens. - Boundary markers: The skill does not provide specific instructions to delimit untrusted project content or ignore embedded instructions.
- Capability inventory: The skill utilizes
get_project_contextandverify_previewtools and has the capability to implement source code changes. - Sanitization: There are no explicit instructions for sanitizing or validating content retrieved from the external project environment.
Audit Metadata