design-router
Pass
Audited by Gen Agent Trust Hub on Apr 4, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it ingests untrusted user requests to influence which local skill files are loaded and scanned. This behavior is consistent with the skill's primary purpose and involves only reading local documentation. Ingestion points: User's project request (SKILL.md, Execution Protocol Step 1). Boundary markers: Absent. Capability inventory: Reading and scanning sections of local SKILL.md files (SKILL.md, Execution Protocol Steps 4-5). Sanitization: Absent.
- [NO_CODE]: The skill consists entirely of Markdown instructions and does not include any scripts, executables, or code-based dependencies.
Audit Metadata