design-template-industrial
Pass
Audited by Gen Agent Trust Hub on Sep 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill acts as a design system reference. It does not perform unauthorized network operations, access sensitive files, or execute remote code.\n- [INDIRECT_PROMPT_INJECTION]: The skill's workflow involves reading and analyzing an existing user codebase to identify design tokens and architecture. This creates an attack surface for indirect prompt injection if the processed codebase contains malicious instructions. However, no specific malicious patterns or instructions to override agent safety guidelines were identified.\n
- Ingestion points: User-provided codebase files (via Read, Glob, and Grep tools).\n
- Boundary markers: The skill does not explicitly define delimiters to separate user-provided code from the agent's internal instructions.\n
- Capability inventory: The skill has permissions to read, write, and edit files, as well as use glob and grep for file system discovery.\n
- Sanitization: No explicit sanitization or filtering of codebase content is mentioned in the instructions.
Audit Metadata