spine-design
Pass
Audited by Gen Agent Trust Hub on Jul 1, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill performs legitimate system design tasks. It identifies existing infrastructure using standard directory listing commands (
ls -a) to gather context for its architectural recommendations. - [PROMPT_INJECTION]: The skill has a surface for indirect prompt injection because it ingests data from local infrastructure files (e.g., database configs, service definitions) to inform its design process.
- Ingestion points: Discovery of local files via
ls -aand theReadtool in Step 0 of SKILL.md. - Boundary markers: The instructions do not define delimiters or specific "ignore instructions" markers for the content read from local files.
- Capability inventory: The skill is authorized to use
Bash,Write,Edit, andWebFetchtools. - Sanitization: No explicit sanitization or validation of local file content is described.
- [SAFE]: The metadata in both SKILL.md and plugin.json is consistent and correctly identifies the author and purpose of the skill. The unusual formatting instructions in the 'Delivery' section appear to be a template artifact and do not impact the safety of the skill.
Audit Metadata