insecure-design

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill consists entirely of instructional documentation and best-practice code examples. It does not include any executable scripts, automated tools, or network-enabled components that could be misused. All code snippets provided are pedagogical examples focused on enhancing application security.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze untrusted user-provided content, such as application architecture descriptions and code for security audits.
  • Ingestion points: The skill triggers on user queries related to design reviews, threat modeling, and business logic analysis as defined in SKILL.md.
  • Boundary markers: There are no explicit instructions to the agent to treat user-provided architecture descriptions as untrusted or to use specific delimiters.
  • Capability inventory: The skill provides no active capabilities; it lacks tool definitions, shell scripts, or network access, limiting the potential impact of any injected instructions.
  • Sanitization: No input sanitization or validation logic is defined for the data being analyzed.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 08:14 PM
Security Audit — agent-trust-hub — insecure-design