intent-init
Pass
Audited by Gen Agent Trust Hub on Oct 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill scans existing project files including documentation and specifications to identify current project state. This process ingests untrusted data from the local file system without explicit boundary markers or instructions to ignore embedded commands.
- Ingestion points: The skill scans file paths such as intent/, specs/, docs/, and files like README.md and DESIGN.md.
- Boundary markers: No specific delimiters or safety instructions are defined to encapsulate the content of scanned files.
- Capability inventory: The skill can perform file system operations including creating directories and generating template files based on its analysis.
- Sanitization: There is no evidence of sanitization or filtering of the scanned file content before it is presented to the agent.
- [COMMAND_EXECUTION]: The skill executes file and directory creation commands as part of its primary initialization workflow. This is standard behavior for a scaffolding tool but is a sensitive capability.
Audit Metadata