103-common-data-model
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests content from existing project documentation and the codebase to build its conceptual model. Malicious instructions embedded in these source files could potentially influence the agent's output during the drafting process.\n
- Ingestion points: Reads existing files (D01, D02) in
.specflow/docs/and explores the repository using the@exploretool to find models and schemas.\n - Boundary markers: Absent; there are no specific delimiters or instructions to ignore embedded prompts within the files being analyzed.\n
- Capability inventory: The skill has the ability to write to the file system at
.specflow/docs/D03-common-data-model.md.\n - Sanitization: Absent; the skill extracts information from source files to populate a markdown template without explicit sanitization of the extracted text.
Audit Metadata