write-spec
Pass
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes data from existing project files which represents an indirect prompt injection surface.\n
- Ingestion points: The skill reads
docs/PRD.mdandfeatures/INDEX.mdto establish project context as defined inSKILL.md.\n - Boundary markers: Absent. Contents from project documents are treated as authoritative context without delimiters or instructions to ignore potential embedded instructions.\n
- Capability inventory: Includes file system inspection via
git ls-filesand file creation or modification within the project repository structure.\n - Sanitization: Absent. Data from ingested documentation is directly used to generate feature specifications and update tracking documents without filtering.
Audit Metadata