design-system

Pass

Audited by Gen Agent Trust Hub on Mar 28, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill reads and processes untrusted data from various Markdown files in the local repository, such as game concepts and existing system documentation. This exposes the agent to indirect prompt injection, where malicious instructions hidden in these files could potentially manipulate the design output or tool usage.
  • Ingestion points: File reads from design/gdd/ and .claude/docs/templates/ directories.
  • Boundary markers: Instructions do not specify delimiters or constraints to prevent the agent from following instructions found within the read data.
  • Capability inventory: The skill utilizes Write, Edit, and Task tools to modify the project state and delegate work to other agents.
  • Sanitization: No content validation or sanitization is performed on the data ingested from files before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 28, 2026, 12:11 PM
Security Audit — agent-trust-hub — design-system