architecture-refinement
Pass
Audited by Gen Agent Trust Hub on Apr 1, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data from user-provided files and links, which constitutes an indirect prompt injection surface.
- Ingestion points: The process instructions in Step 1 explicitly direct the agent to 'Start from the user prompt and the attached files or links' and to use an 'app spec (might be an attached md file)' to answer questions.
- Boundary markers: The skill lacks explicit instructions for the agent to use delimiters or to disregard instructions that might be embedded within the processed external files.
- Capability inventory: The skill's primary function is to generate a structured YAML output. No capabilities for shell command execution, file system modification, or direct network operations are specified within the instruction set.
- Sanitization: There are no specified procedures for sanitizing or validating the content extracted from external documents before it is interpolated into the agent's reasoning process.
Audit Metadata