brainstorm
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from local project documentation and source code which could contain malicious instructions.
- Ingestion points: Reads files such as
docs/SUMMARY.md,Code Standarddocuments, and implementation files in SKILL.md. - Boundary markers: No specific delimiters or instructions to ignore embedded commands are defined for the ingested files.
- Capability inventory: The skill has file system read access and write access to the
docs/.brainstorms/directory, along with interactive user input capabilities. - Sanitization: No validation or filtering is mentioned for the content of the files read during the context gathering phase.
Audit Metadata