design-a11y
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill uses tools like Read, Grep, and Glob to analyze design documents such as _design/SIZING.md and _design/PROVENANCE.md. These files represent ingestion points for untrusted data that lacks explicit boundary markers or sanitization, creating an attack surface where embedded instructions in project files could potentially influence the agent's behavior. Capability inventory includes the use of Bash and Write tools.
- [DYNAMIC_EXECUTION]: The skill documentation references a local verification script, refute.py, to be used for validating design claims. The execution of local scripts using the Bash tool to process data derived from the project environment constitutes a dynamic execution risk, although the script is presented as a legitimate local utility.
Audit Metadata