diagram-quality
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructions define how the agent should interpret and respond to feedback signals, creating a surface for indirect prompt injection from external inputs.
- Ingestion points: The agent is instructed to process data from the
design_feedbacktool, which includes human-provided chat messages and element annotations (referenced in SKILL.md and references/_conversation.md). - Boundary markers: The provided rules do not include specific delimiters or instructions to ignore potential injection patterns within the ingested feedback.
- Capability inventory: The agent utilizes tools such as
design_create,diagram_upsert,design_feedback, anddesign_exportto modify diagrams and export designs based on input. - Sanitization: The skill lacks explicit guidance for sanitizing or validating external feedback before it is used to drive subsequent tool calls.
Audit Metadata