design-sprint

Warn

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSPROMPT_INJECTIONNO_CODE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs users to install a full implementation via a plugin command or by cloning a repository from an external source (https://github.com/aoshimash/skills). This source is not recognized as a trusted organization or well-known service.
  • [PROMPT_INJECTION]: The workflow described in the documentation creates a surface for indirect prompt injection:
  • Ingestion points: Phase 1 (Research) involves reading an external codebase (SKILL.md).
  • Boundary markers: No specific delimiters or instructions are provided to help the agent ignore malicious instructions embedded in the analyzed code.
  • Capability inventory: The skill possesses the capability to write and push issue hierarchies to external trackers like GitHub and GitLab (SKILL.md).
  • Sanitization: There is no evidence of content sanitization or validation for data ingested from the codebase.
  • [NO_CODE]: The provided files consist solely of YAML metadata and Markdown documentation; they do not contain any executable scripts or logic.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 13, 2026, 10:44 AM
Security Audit — agent-trust-hub — design-sprint