qa-spec-auditor
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes potentially untrusted external data during its audit workflow, creating a vulnerability surface.
- Ingestion points: The skill ingests data from live UI content via Playwright, OpenAPI specifications, requirements documents, and test results (SKILL.md).
- Boundary markers: The instructions do not define specific delimiters or warnings to prevent the agent from potentially obeying instructions embedded within the audited content.
- Capability inventory: The skill possesses file system write access for report generation, UI exploration capabilities via Playwright, and repository change tracking via GitHub MCP (SKILL.md).
- Sanitization: There is no evidence of sanitization or validation protocols for content ingested from external or third-party sources.
Audit Metadata