design-direction

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external 'references' such as links, screenshots, and brand identities, which act as ingestion points for untrusted data. Ingestion points: Reference collection is outlined in SKILL.md and detailed in playbooks/reference-analysis.md. Boundary markers: No formal prompt boundaries or 'ignore embedded instructions' warnings are present for external content. Capability inventory: The skill allows access to Bash, Write, Read, Grep, and Glob tools, providing a wide surface for exploitation if instructions are injected. Sanitization: The skill lacks explicit sanitization or validation logic for the external references.
  • [REMOTE_CODE_EXECUTION]: The skill instructions in SKILL.md reference a script named refute.py to be used for validating design choices. This script is missing from the skill manifest. Evidence: SKILL.md contains a table entry linking to [refute](refute.py) for evaluating expensive design claims. Risk: Since the agent is granted Bash tool access, it may attempt to execute this missing script. If a script with this name exists in the environment or is introduced by an attacker, it represents an unverified code execution path.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 10:24 AM
Security Audit — agent-trust-hub — design-direction