201-high-level-design
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill has a vulnerability surface for indirect prompt injection as it ingests untrusted data from multiple sources to generate documentation.
- Ingestion points: In Step 1 and Step 2, the skill reads local files such as
.specflow/docs/D10-feature-overview.md,D01,D02,D07, anddomain-knowledge.md, as well as user-provided feature descriptions. - Boundary markers: The instructions lack explicit delimiters or warnings to the agent to ignore potentially malicious instructions embedded within the source documents or user input.
- Capability inventory: The skill is authorized to perform file-read and file-write operations within the workspace.
- Sanitization: There is no evidence of content validation or escaping of external data before it is interpolated into the drafting process.
Audit Metadata