design-gate
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection as it processes untrusted external data to drive its workflow.
- Ingestion points: The skill ingests user-provided plans, slice contracts, and code diff scopes (SKILL.md, Workflow Step 1).
- Boundary markers: There are no explicit instructions or delimiters defined to isolate input data or warn subagents to ignore embedded instructions within the plans.
- Capability inventory: Based on the input analysis, the skill triggers the execution of multiple specialized subagents (such as
macro-architecture,domain-driven-design, andarchitecture-lens) and merges their outputs. - Sanitization: The instructions do not define any sanitization, validation, or filtering of the input content before it is processed by the lens skills.
Audit Metadata