design-audit
Pass
Audited by Gen Agent Trust Hub on May 19, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: Indirect prompt injection surface identified through project-level configuration files.\n
- Ingestion points: The skill reads project-specific files
.design-context.mdand.design-critique/ignore.mdfrom the current repository (SKILL.md).\n - Boundary markers: Absent. The skill instructions do not specify the use of delimiters or warnings to treat the content of these external files as untrusted data.\n
- Capability inventory: The agent executing the skill has standard file system access and is instructed to suggest follow-up commands (e.g.,
/design-polish).\n - Sanitization: Absent. The skill instructions direct the agent to 'silently drop' audit findings that match strings in the user-provided ignore list, which allows external data to override the audit output.\n- [SAFE]: The skill references reference materials and heuristics from associated vendor resources (minoan-frontend-design) located in the user's home directory.
Audit Metadata