ground-design-in-codebase

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill follows security best practices by explicitly prohibiting the AI from implementing or modifying product code, configuration, or external state, limiting it to providing an authorized review artifact.
  • [INDIRECT_PROMPT_INJECTION]: The skill analyzes external data including specifications and source code, which provides an entry point for indirect prompt injection. This is mitigated by the skill's lack of write or execution capabilities.
  • Ingestion points: Specifications and code contents provided as task evidence in SKILL.md.
  • Boundary markers: No delimiters are specified to separate instructions from data.
  • Capability inventory: The skill is restricted from writing to the filesystem or performing network operations.
  • Sanitization: No sanitization of the review evidence is specified.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 12:56 PM
Security Audit — agent-trust-hub — ground-design-in-codebase