design-template-bauhaus

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to audit and analyze an existing codebase's tech stack, design tokens, and architecture before proposing changes. This ingestion of untrusted data from the user's project files represents a surface for indirect prompt injection if those files contain malicious instructions.
  • Ingestion points: The instructions in SKILL.md require the agent to identify tech stacks, design tokens, and architecture from the current system.
  • Boundary markers: There are no explicit instructions to use delimiters or ignore embedded instructions when reading codebase files.
  • Capability inventory: The skill utilizes Read, Write, Edit, Glob, and Grep tools to modify the environment.
  • Sanitization: No sanitization or validation of the ingested codebase content is specified.
  • [EXTERNAL_DOWNLOADS]: The design specification references fetching the 'Outfit' font family from Google Fonts, which is a well-known service.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 08:38 AM
Security Audit — agent-trust-hub — design-template-bauhaus