102-system-architecture
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill has a surface for indirect prompt injection as it processes untrusted content from the repository to generate documentation.
- Ingestion points: The skill reads existing project documentation (specifically
D01) and explores the codebase using the@exploretool to resolve technology choices. - Boundary markers: There are no explicit delimiters or instructions to ignore embedded commands when the agent processes the retrieved repository content.
- Capability inventory: The skill's capabilities are restricted to reading local files and writing markdown documentation to
.specflow/docs/D02-system-architecture.md. It does not possess network access or arbitrary command execution capabilities. - Sanitization: The skill does not perform sanitization or validation of the data ingested from the repository before it is interpolated into the drafting process.
Audit Metadata