feature-forge
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill functions as a structured documentation assistant, utilizing local reference files to guide the creation of requirements specifications. No evidence of malicious command execution, credential theft, or obfuscation was found.
- [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it integrates user input and subagent results into generated documentation.
- Ingestion points: Untrusted data enters via the
AskUserQuestionstool in SKILL.md and results from technical subagents described in references/pre-discovery-subagents.md. - Boundary markers: The skill employs structured markdown templates (EARS syntax and Given-When-Then format) which provide organizational delimiters for the content.
- Capability inventory: The skill's primary capability is writing markdown files to the local
specs/directory. - Sanitization: No explicit sanitization or filtering of the external content is performed before interpolation into the final document templates.
Audit Metadata