create-spec
Pass
Audited by Gen Agent Trust Hub on Aug 25, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and summarize content from the
research/directory to generate technical specifications. This creates a surface for indirect prompt injection if an attacker can influence the content of files within that directory. - Ingestion points: The agent is instructed to read all files in the
research/directory or a specific path provided via$ARGUMENTSinSKILL.md. - Boundary markers: The prompt lacks explicit delimiters (like XML tags or triple quotes) or 'ignore instructions' warnings when processing the research data.
- Capability inventory: The skill has the capability to write files to the
specs/directory and execute shell commands (via thebashtool) to open HTML visualizations. - Sanitization: There is no mention of sanitizing or validating the content of the research documents before they are used to generate the specification.
- [DYNAMIC_CONTEXT_INJECTION]: The
SKILL.mdfile contains a technical design template that uses the!command`` syntax to dynamically populate metadata. - Evidence: The field
Author(s)in the Markdown table contains!git config user.name. - Risk: This command executes on the host system at the time the skill is loaded to retrieve the user's name. While this specific command is benign and serves a legitimate utility purpose, the mechanism itself is a powerful feature that should be monitored.
- [COMMAND_EXECUTION]: The skill provides explicit instructions and a shell script block for the agent to use the system's
bashtool. - Context: The instructions tell the agent to use
open(macOS) orxdg-open(Linux) to display generated HTML visualizations to the user. - Evidence: A conditional bash block in
SKILL.mdhandles cross-platform file opening.
Audit Metadata