design-with-claude

Pass

Audited by Gen Agent Trust Hub on Aug 31, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill promotes the installation of a plugin from an external GitHub repository (github.com/imsaif/design-with-claude) which is not a verified source.
  • [INDIRECT_PROMPT_INJECTION]: The skill acts as a delivery mechanism for instructions hosted externally, introducing a risk of agent behavior manipulation.
  • Ingestion points: Markdown content from github.com/imsaif/design-with-claude is loaded into the agent's prompt context.
  • Boundary markers: No specific delimiters or safety instructions are present in the stub to isolate the external instructions.
  • Capability inventory: The skill claims to implement 38 specialist agents, which would significantly expand the agent's instruction set without direct audit.
  • Sanitization: No filtering or validation of the incoming remote instructions is performed by this stub.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 31, 2026, 08:25 PM
Security Audit — agent-trust-hub — design-with-claude