202-spec-design

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection by reading external content and using it to generate output files.
  • Ingestion points: The skill reads project documentation from .specflow/features/<fid>-<feature-slug>/overview.md, .specflow/docs/D01-project-overview.md, .specflow/docs/D07-ui-experience.md, and .specflow/context/domain-knowledge.md.
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to treat the content of these external files as untrusted or to ignore any embedded instructions within them.
  • Capability inventory: The skill possesses the capability to write to the file system (.specflow/features/<fid>-<feature-slug>/specs.feature).
  • Sanitization: The instructions do not include steps to sanitize or validate the content of the ingested files before using them to generate the Gherkin scenarios.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 06:51 PM
Security Audit — agent-trust-hub — 202-spec-design