feature-design-assistant
Pass
Audited by Gen Agent Trust Hub on Mar 31, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill presents a surface for indirect prompt injection. 1. Ingestion points: The exploration of the project structure and tech stack in Phase 1. 2. Boundary markers: No delimiters or ignore-instructions are specified for the context discovery phase. 3. Capability inventory: The skill can write files to the project's documentation directory in Phase 5. 4. Sanitization: There is no requirement to sanitize or escape data read from the codebase before including it in the generated designs.
- [SAFE]: The skill's primary logic relies on user-driven interactive questions, which limits autonomous risky behavior.
- [SAFE]: No unauthorized network activity, hardcoded secrets, or obfuscation techniques were identified in the skill instructions.
Audit Metadata