100-domain-knowledge
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill utilizes web search to collect domain information (Step 4), which is subsequently synthesized and written to a file within the project repository (Step 8). This creates a vulnerability where malicious instructions or deceptive content found on external websites could influence the agent's synthesis or the resulting documentation.
- Ingestion points: External web content retrieved during the 'live research pass' in SKILL.md.
- Boundary markers: The instructions lack explicit delimiters or warnings to ignore instructions that might be embedded within the retrieved search results.
- Capability inventory: The skill has permissions to read local context files (D01, D10) and write to the local filesystem (.specflow/context/domain-knowledge.md).
- Sanitization: The skill does not define any specific mechanisms to sanitize or filter external data before it is integrated into the final document.
Audit Metadata