design-dispatch

Pass

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill includes proactive security measures against indirect prompt injection. It explicitly instructs the model to treat all external inputs, such as page content, pull request bodies, and filenames, as untrusted data.
  • Ingestion points: Page content, PR bodies, and filenames.
  • Boundary markers: The skill relies on strong instructional guardrails to ignore embedded instructions rather than specific character delimiters.
  • Capability inventory: The skill itself is a read-only router and does not contain any code execution or file-writing capabilities; it delegates actions to other specialized skills.
  • Sanitization: Explicit instructions in the 'External Side Effects' and 'Anti-Patterns' sections mandate that the agent act only on user chat input and treat all other observed content as inert data.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 20, 2026, 01:29 PM
Security Audit — agent-trust-hub — design-dispatch