feature-forge

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill functions as a structured documentation assistant, utilizing local reference files to guide the creation of requirements specifications. No evidence of malicious command execution, credential theft, or obfuscation was found.
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it integrates user input and subagent results into generated documentation.
  • Ingestion points: Untrusted data enters via the AskUserQuestions tool in SKILL.md and results from technical subagents described in references/pre-discovery-subagents.md.
  • Boundary markers: The skill employs structured markdown templates (EARS syntax and Given-When-Then format) which provide organizational delimiters for the content.
  • Capability inventory: The skill's primary capability is writing markdown files to the local specs/ directory.
  • Sanitization: No explicit sanitization or filtering of the external content is performed before interpolation into the final document templates.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:48 PM
Security Audit — agent-trust-hub — feature-forge