design-brief

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to scan local project files, such as CSS variables and Tailwind configurations, to extract design patterns. This creates an attack surface where malicious instructions embedded in those files could influence the agent's behavior during the brief creation process.
  • [NO_CODE]: The skill is entirely instruction-based and does not include any external scripts, binaries, or dependencies, which limits the potential for direct malicious code execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 09:34 PM
Security Audit — agent-trust-hub — design-brief