design-system
Pass
Audited by Gen Agent Trust Hub on Mar 28, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill reads and processes untrusted data from various Markdown files in the local repository, such as game concepts and existing system documentation. This exposes the agent to indirect prompt injection, where malicious instructions hidden in these files could potentially manipulate the design output or tool usage.
- Ingestion points: File reads from
design/gdd/and.claude/docs/templates/directories. - Boundary markers: Instructions do not specify delimiters or constraints to prevent the agent from following instructions found within the read data.
- Capability inventory: The skill utilizes
Write,Edit, andTasktools to modify the project state and delegate work to other agents. - Sanitization: No content validation or sanitization is performed on the data ingested from files before processing.
Audit Metadata