design-audit

Pass

Audited by Gen Agent Trust Hub on May 19, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Indirect prompt injection surface identified through project-level configuration files.\n
  • Ingestion points: The skill reads project-specific files .design-context.md and .design-critique/ignore.md from the current repository (SKILL.md).\n
  • Boundary markers: Absent. The skill instructions do not specify the use of delimiters or warnings to treat the content of these external files as untrusted data.\n
  • Capability inventory: The agent executing the skill has standard file system access and is instructed to suggest follow-up commands (e.g., /design-polish).\n
  • Sanitization: Absent. The skill instructions direct the agent to 'silently drop' audit findings that match strings in the user-provided ignore list, which allows external data to override the audit output.\n- [SAFE]: The skill references reference materials and heuristics from associated vendor resources (minoan-frontend-design) located in the user's home directory.
Audit Metadata
Risk Level
SAFE
Analyzed
May 19, 2026, 04:39 PM
Security Audit — agent-trust-hub — design-audit