hackathon-guide
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied inputs (project ideas, learner profiles, and technical background) to generate the PRD, technical specifications, and build checklists. In autonomous mode, the agent then uses the Agent tool to execute these generated steps. This creates an indirect prompt injection surface where malicious instructions embedded in a user's initial project description or requirements could influence the agent's behavior during the automated build phase.
- Ingestion points: User responses during the /scope, /prd, and /spec interview phases, which are stored in doc/ artifacts.
- Boundary markers: The provided templates (scope-template.md, prd-template.md, etc.) do not include instructions for using delimiters or warnings to ignore embedded instructions when processing user data.
- Capability inventory: The skill instructs the agent to perform file-write operations to the docs/ directory and process-notes.md, and to utilize the Agent tool for task dispatching.
- Sanitization: There are no instructions for validating or sanitizing user input before it is interpolated into downstream instructions or artifacts.
- [COMMAND_EXECUTION]: The /build workflow involves carrying out technical tasks defined in the checklist, such as running development servers or executing verification commands. While these actions are central to the skill's pedagogical purpose, they involve the execution of shell commands based on requirements formulated from untrusted user input.
Audit Metadata