design-amplify
Pass
Audited by Gen Agent Trust Hub on Mar 23, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: Indirect prompt injection surface identified through project file ingestion and file modification capabilities.
- Ingestion points: Reads project-level files including package.json, pubspec.yaml, build.gradle, Podfile, and local theme configuration files.
- Boundary markers: None. The skill does not implement delimiters or instructions for the agent to ignore content that might mimic instructions within analyzed files.
- Capability inventory: The skill modifies local codebase files, specifically updating CSS, Dart (Flutter), and design token configurations (Section 3.3).
- Sanitization: None. The content of configuration files is processed directly without escaping or validation.
- [COMMAND_EXECUTION]: The skill performs file system operations to read build configurations and write updated design tokens and styles to the local environment.
Audit Metadata