design-code-architecture

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill collects user input regarding application architecture and project specifics, which is then used to generate or modify documentation files in the project's docs/ directory.
  • Ingestion points: User responses to intake questions (e.g., feature descriptions, tech stack, load estimates) and phase-specific design decisions in SKILL.md.
  • Boundary markers: The instructions do not specify the use of delimiters or warnings to ignore potentially malicious instructions embedded in the user-provided content when writing to files.
  • Capability inventory: The skill is designed to create and modify files in the project's docs/ folder (docs/ARCHITECTURE.md, docs/RELIABILITY.md, etc.) as described in SKILL.md.
  • Sanitization: There is no explicit requirement for the agent to sanitize or validate the user's input before recording it in the project artifacts.
  • [EXTERNAL_DOWNLOADS]: The skill includes instructions to guide the user in manually installing additional modular skills from the author's collection using the standard npx package runner.
  • Evidence: SKILL.md contains instructions to offer the command 'npx skills add wondelai/skills/ --global' to the user if a specific sub-skill is missing.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 12:05 PM
Security Audit — agent-trust-hub — design-code-architecture