quick-design
Pass
Audited by Gen Agent Trust Hub on Apr 8, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements a workflow for design documentation within a project's internal directory structure.
- [INDIRECT_PROMPT_INJECTION]: The skill demonstrates an attack surface for indirect prompt injection by ingesting data from external files while possessing write capabilities.
- Ingestion points: The skill reads from design/gdd/, design/quick-specs/, and assets/data/ files during the context scan phase in SKILL.md.
- Boundary markers: There are no explicit instructions to use delimiters or ignore potentially malicious instructions embedded within the source documents.
- Capability inventory: The skill utilizes Write and Edit tools to generate new specs in design/quick-specs/ and update existing GDD files.
- Sanitization: No input validation or sanitization mechanisms are specified for the content read from the project files.
Audit Metadata