100-domain-knowledge

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill utilizes web search to collect domain information (Step 4), which is subsequently synthesized and written to a file within the project repository (Step 8). This creates a vulnerability where malicious instructions or deceptive content found on external websites could influence the agent's synthesis or the resulting documentation.
  • Ingestion points: External web content retrieved during the 'live research pass' in SKILL.md.
  • Boundary markers: The instructions lack explicit delimiters or warnings to ignore instructions that might be embedded within the retrieved search results.
  • Capability inventory: The skill has permissions to read local context files (D01, D10) and write to the local filesystem (.specflow/context/domain-knowledge.md).
  • Sanitization: The skill does not define any specific mechanisms to sanitize or filter external data before it is integrated into the final document.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 06:51 PM
Security Audit — agent-trust-hub — 100-domain-knowledge