design-md-author

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input from source code and design briefs, which creates a potential surface for indirect prompt injection. 1. Ingestion points: Source files, images, tokens, and user briefs in SKILL.md. 2. Boundary markers: Explicit instructions to treat retrieved instructions as data, not authority. 3. Capability inventory: File system read and write for documentation. 4. Sanitization: Directives to avoid executing embedded instructions.
  • [EXTERNAL_DOWNLOADS]: The skill references an external specification for interoperability. Evidence: references/format-and-validation.md links to the Google Labs design.md GitHub repository, which is a trusted source.
  • [DATA_EXFILTRATION]: The skill includes constraints against unauthorized data handling. Evidence: SKILL.md specifies that the skill does not authorize exporting remote tokens.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 06:57 PM
Security Audit — agent-trust-hub — design-md-author