design-template-retro

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze and modify a user's codebase to implement a design system, creating an attack surface where untrusted data (the codebase) could influence agent behavior.
  • Ingestion points: The skill instructs the agent to read the user's current tech stack, design tokens, and component architecture as defined in the role instructions in SKILL.md.
  • Boundary markers: No specific boundary markers or instructions to ignore embedded commands in the processed code are provided.
  • Capability inventory: The skill requests and uses Read, Write, Edit, Glob, and Grep tools, allowing it to modify the filesystem.
  • Sanitization: No specific sanitization or validation of the ingested code is described.
  • [NO_CODE]: The skill consists entirely of markdown instructions and CSS snippets; it does not include any executable scripts, binaries, or automated shell commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 08:38 AM
Security Audit — agent-trust-hub — design-template-retro