software-design

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external requirement documents and user conversation context to generate design documentation, representing a potential injection surface.
  • Ingestion points: Input consists of requirement documents and conversation context as defined in SKILL.md.
  • Boundary markers: There are no explicit delimiters defined to separate untrusted input data from instructions.
  • Capability inventory: The skill instructions guide the agent to perform file writing operations to create design documents.
  • Sanitization: The skill includes a 'Sensitive information' check in its review list to ensure real credentials (passwords, keys, tokens) are replaced with placeholders in generated files.
  • [SAFE]: No malicious patterns such as command execution, network exfiltration, or obfuscation were detected. The skill follows security best practices by explicitly instructing the agent to avoid including sensitive data in the output documents.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 11:45 AM
Security Audit — agent-trust-hub — software-design