203-implementation-design

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection by reading and processing data from external project files that could contain hidden instructions.- Ingestion points: In Step 1, the skill reads .specflow/features/<fid>-<feature-slug>/overview.md and specs.feature. In Step 2, it reads architecture documents D01-D08 and domain-knowledge.md.- Boundary markers: The instructions do not specify the use of delimiters or 'ignore embedded instructions' warnings when reading these files.- Capability inventory: The skill uses the @explore tool to investigate the codebase and has the authority to write new implementation design files to the project directory (Step 10).- Sanitization: There is no mention of escaping, validating, or filtering the content of the ingested files before the agent uses them to generate the implementation design.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 06:51 PM
Security Audit — agent-trust-hub — 203-implementation-design