design-audit

Pass

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill functions as a static analysis engine that reads local source code and configuration files to generate a design audit report. It does not include commands for network communication, external downloads, or execution of arbitrary code.\n- [PROMPT_INJECTION]: The skill has a surface for indirect prompt injection because it processes untrusted file content (source code, package manifests, and markdown documentation) without utilizing explicit boundary markers or 'ignore' instructions for the embedded content. This could allow an attacker to attempt to manipulate the audit results via malicious comments in the code. The impact is limited to the accuracy of the generated report.\n
  • Ingestion points: UI components, package.json, pubspec.yaml, requirements.txt, build.gradle, and CLAUDE.md.\n
  • Boundary markers: None defined to isolate the content of the analyzed files.\n
  • Capability inventory: File system read access and writing results to MEMORY.md.\n
  • Sanitization: No evidence of data sanitization or validation logic for the ingested file content.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 23, 2026, 10:59 AM
Security Audit — agent-trust-hub — design-audit