insecure-design
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill consists entirely of instructional documentation and best-practice code examples. It does not include any executable scripts, automated tools, or network-enabled components that could be misused. All code snippets provided are pedagogical examples focused on enhancing application security.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze untrusted user-provided content, such as application architecture descriptions and code for security audits.
- Ingestion points: The skill triggers on user queries related to design reviews, threat modeling, and business logic analysis as defined in SKILL.md.
- Boundary markers: There are no explicit instructions to the agent to treat user-provided architecture descriptions as untrusted or to use specific delimiters.
- Capability inventory: The skill provides no active capabilities; it lacks tool definitions, shell scripts, or network access, limiting the potential impact of any injected instructions.
- Sanitization: No input sanitization or validation logic is defined for the data being analyzed.
Audit Metadata