pie-blueprint-engine
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill ingests engineering calculations to populate drawing tags, labels, and metadata in SVG/DXF outputs, creating a potential surface for indirect prompt injection if the input data contains malicious instructions.
- Ingestion points: Data provided from fluid-systems, power-systems, and thermal-engineering calculation records.
- Boundary markers: The prompt templates do not include specific delimiters or 'ignore instructions' warnings for the interpolated data.
- Capability inventory: The skill is granted access to Bash, Read, Grep, and Glob tools.
- Sanitization: The instructions do not describe a process for escaping or validating external content before it is interpolated into the SVG XML structure.
Audit Metadata