design-brief
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to scan local project files, such as CSS variables and Tailwind configurations, to extract design patterns. This creates an attack surface where malicious instructions embedded in those files could influence the agent's behavior during the brief creation process.
- [NO_CODE]: The skill is entirely instruction-based and does not include any external scripts, binaries, or dependencies, which limits the potential for direct malicious code execution.
Audit Metadata