aidlc-outcomes-pack
Pass
Audited by Gen Agent Trust Hub on Oct 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the workspace to generate a summary report, creating a potential surface for indirect prompt injection.
- Ingestion points: In
SKILL.md, Step 2 specifies reading 'All artefacts recursively under //' and 'The delivered application and infrastructure code at the workspace root.' - Boundary markers: No specific delimiters or 'ignore' instructions are provided to the agent to distinguish between data and potential instructions within the source files.
- Capability inventory: The skill executes local commands via
{{INVOKE}} engine runtime summaryand performs file writes toOUTCOMES.md. - Sanitization: There is no evidence of sanitization, escaping, or validation of the content read from the workspace before it is processed by the agent.
- [COMMAND_EXECUTION]: The skill invokes the
engine runtime summary --jsoncommand to gather workflow statistics using the platform's tool invocation syntax.
Audit Metadata