state-model
Pass
Audited by Gen Agent Trust Hub on May 19, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: Indirect prompt injection and user argument interpolation surface identified.\n
- Ingestion points: The skill ingests data from user-provided
$ARGUMENTSand various repository source files, including routes, components, database schemas, and API endpoints.\n - Boundary markers: There are no boundary markers or delimiters defined in
SKILL.mdto isolate instructions from the ingested project data, nor are there instructions to disregard embedded commands.\n - Capability inventory: The agent has the capability to read project source files and metadata, and is explicitly instructed to write documentation to the local filesystem (
docs/hci/state-model.md), including directory creation.\n - Sanitization: No content sanitization, validation, or escaping is performed on the ingested data before it is processed by the agent.
Audit Metadata