technical-lead-role
Pass
Audited by Gen Agent Trust Hub on Mar 16, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill uses authoritative language (e.g., 'CRITICAL', 'MANDATORY') to enforce workflow boundaries and delegation rules. These instructions are part of the defined role-play and do not represent attempts to bypass safety filters or disregard system instructions.\n- [PROMPT_INJECTION]: Indirect prompt injection vulnerability surface detected.\n
- Ingestion points: The agent is instructed to read contents from
CLAUDE.mdfiles (viaReadtool) and project backlog data (viatask_searchandtask_list).\n - Boundary markers: Absent. Prompt templates for delegation (e.g.,
prompt=\"Complete task-X: [task title]\") do not use delimiters or explicit 'ignore embedded instructions' warnings for the interpolated data.\n - Capability inventory: The main thread possesses significant capabilities including repository commits (
git commit), task state management (task_edit), and the ability to spawn and instruct subagents (Tasktool).\n - Sanitization: There is no mention of sanitizing or validating input from project files or backlog data before it is processed or passed to other tools and agents.
Audit Metadata