quick-design

Pass

Audited by Gen Agent Trust Hub on Apr 8, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a workflow for design documentation within a project's internal directory structure.
  • [INDIRECT_PROMPT_INJECTION]: The skill demonstrates an attack surface for indirect prompt injection by ingesting data from external files while possessing write capabilities.
  • Ingestion points: The skill reads from design/gdd/, design/quick-specs/, and assets/data/ files during the context scan phase in SKILL.md.
  • Boundary markers: There are no explicit instructions to use delimiters or ignore potentially malicious instructions embedded within the source documents.
  • Capability inventory: The skill utilizes Write and Edit tools to generate new specs in design/quick-specs/ and update existing GDD files.
  • Sanitization: No input validation or sanitization mechanisms are specified for the content read from the project files.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 8, 2026, 06:28 PM