project-context

Pass

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection because it ingests and processes untrusted data from the repository (such as UI code, routes, and package metadata) to generate documentation files. Instructions in these files could potentially influence agent behavior.\n
  • Ingestion points: The skill reads PRODUCT.md, DESIGN.md, package metadata, route definitions, and UI components from the project directory.\n
  • Boundary markers: The agent is instructed to explain changes before overwriting files and report evidence for its documentation, providing a level of manual review.\n
  • Capability inventory: The skill is capable of reading and writing files within the project environment.\n
  • Sanitization: The instructions do not specify methods for sanitizing or filtering instructions that might be embedded within the project files it analyzes.\n- [EXTERNAL_DOWNLOADS]: References the design.md specification from a well-known repository (google-labs-code on GitHub) to define the documentation format.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 15, 2026, 03:27 AM
Security Audit — agent-trust-hub — project-context