design-gate

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection as it processes untrusted external data to drive its workflow.
  • Ingestion points: The skill ingests user-provided plans, slice contracts, and code diff scopes (SKILL.md, Workflow Step 1).
  • Boundary markers: There are no explicit instructions or delimiters defined to isolate input data or warn subagents to ignore embedded instructions within the plans.
  • Capability inventory: Based on the input analysis, the skill triggers the execution of multiple specialized subagents (such as macro-architecture, domain-driven-design, and architecture-lens) and merges their outputs.
  • Sanitization: The instructions do not define any sanitization, validation, or filtering of the input content before it is processed by the lens skills.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 12:27 AM
Security Audit — agent-trust-hub — design-gate