quick-implement
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and act upon project documentation and source code which could contain malicious instructions designed to influence the agent's behavior during implementation or verification steps.
- Ingestion points: The workflow in
SKILL.mdexplicitly instructs the agent to readdocs/SUMMARY.md,Code Standarddocuments, and other task-relevant detail documents. - Boundary markers: There are no instructions for the agent to use delimiters or specific safety markers to distinguish between legitimate documentation and potential instructions embedded within that data.
- Capability inventory: The skill has the capability to write to the local file system (Step 2: Implement) and execute commands for testing, linting, and building (Step 3: Verify).
- Sanitization: The skill does not define any methods for sanitizing, validating, or filtering the content of the documentation files before they are processed by the agent.
Audit Metadata