design-md-author
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input from source code and design briefs, which creates a potential surface for indirect prompt injection. 1. Ingestion points: Source files, images, tokens, and user briefs in
SKILL.md. 2. Boundary markers: Explicit instructions to treat retrieved instructions as data, not authority. 3. Capability inventory: File system read and write for documentation. 4. Sanitization: Directives to avoid executing embedded instructions. - [EXTERNAL_DOWNLOADS]: The skill references an external specification for interoperability. Evidence:
references/format-and-validation.mdlinks to the Google Labsdesign.mdGitHub repository, which is a trusted source. - [DATA_EXFILTRATION]: The skill includes constraints against unauthorized data handling. Evidence:
SKILL.mdspecifies that the skill does not authorize exporting remote tokens.
Audit Metadata