threat-modeling

Pass

Audited by Gen Agent Trust Hub on Jul 2, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection because it is designed to ingest and analyze untrusted user documents such as PRDs and architecture descriptions. However, it incorporates robust defensive measures: 1. Ingestion points: User-provided system designs and documentation files referenced in SKILL.md. 2. Boundary markers: Section 8 (Safety Notice) contains explicit instructions for the AI to treat analyzed content as data and ignore any embedded directives like 'ignore previous instructions'. 3. Capability inventory: Tool usage is limited to read-only operations (Read, Grep, Glob) in the frontmatter. 4. Sanitization: The skill mandates that the agent redact credentials and secrets found during analysis before producing the threat register.
  • [SAFE]: No malicious code, obfuscation, or unauthorized exfiltration patterns were detected. The skill methodology follows industry-standard security practices and links only to reputable documentation from Microsoft, OWASP, and NIST.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 2, 2026, 01:37 PM
Security Audit — agent-trust-hub — threat-modeling