app-design

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data from existing codebases (source code, documentation, and manifests) which could contain malicious instructions targeted at the agent.\n
  • Ingestion points: Files are read using the read and grep tools during the Discovery phase in references/existing-project.md.\n
  • Boundary markers: The instructions do not specify the use of delimiters or explicit 'ignore instructions' warnings when processing external file content.\n
  • Capability inventory: The skill has significant capabilities, including shell access via bash for running builds and tests, as well as write and edit for modifying the filesystem.\n
  • Sanitization: There is no automated sanitization or filtering of the content ingested from the audited project files, relying instead on manual user verification steps.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 01:16 AM
Security Audit — agent-trust-hub — app-design