design-amplify

Pass

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: Indirect prompt injection surface identified through project file ingestion and file modification capabilities.
  • Ingestion points: Reads project-level files including package.json, pubspec.yaml, build.gradle, Podfile, and local theme configuration files.
  • Boundary markers: None. The skill does not implement delimiters or instructions for the agent to ignore content that might mimic instructions within analyzed files.
  • Capability inventory: The skill modifies local codebase files, specifically updating CSS, Dart (Flutter), and design token configurations (Section 3.3).
  • Sanitization: None. The content of configuration files is processed directly without escaping or validation.
  • [COMMAND_EXECUTION]: The skill performs file system operations to read build configurations and write updated design tokens and styles to the local environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 23, 2026, 10:59 AM
Security Audit — agent-trust-hub — design-amplify