headroom
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests user-supplied load metrics and architectural requirements which are then interpolated into design artifacts written to the local filesystem, creating a potential surface for injection.
- Ingestion points: User-provided traffic statistics, request profiles, and availability needs (SKILL.md).
- Boundary markers: Absent; the skill does not specify delimiters or instructions to isolate untrusted user data.
- Capability inventory: Writing markdown documentation to the
docs/design/directory (SKILL.md). - Sanitization: Absent; the instructions do not include validation or escaping steps for user-supplied data before it is persisted to disk.
Audit Metadata