create-design-doc

Pass

Audited by Gen Agent Trust Hub on Aug 21, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides a structured process for creating documentation. It limits file operations to specified target paths and contains internal verification steps to ensure the accuracy of the final document. Access to configuration templates is restricted to the skill's own configuration directory (~/.claude/skills-config/).
  • [PROMPT_INJECTION]: The skill ingests untrusted data from external local plans and prototypes (Workflow Step 1). Although there are no specific boundary markers or sanitization logic defined for this input, the risk is limited because the skill's capabilities are constrained to file reading and writing (Workflow Steps 4 and 5), without access to network-based exfiltration tools or arbitrary command execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 21, 2026, 03:11 AM
Security Audit — agent-trust-hub — create-design-doc