1-start
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill implements a persistent state mechanism where user interview responses are saved to a
learner-profile.mdfile intended for use by downstream skills (e.g.,2-scope,3-prd). This ingestion of untrusted data into the agent's long-term context creates a vulnerability surface for indirect prompt injection. * Ingestion points: User interview answers collected viaSKILL.md. * Boundary markers: Thetemplates/learner-profile-template.mduses Markdown headers to delimit sections of the profile. * Capability inventory: The skill has file system write permissions for thedevpost/directory. * Sanitization: There is no explicit sanitization of user-provided strings before they are recorded in the profile. - [SAFE]: The skill demonstrates high security awareness by implementing a folder check to prevent execution in sensitive directories, ensuring personal context is excluded from git commits, and providing a direct negative constraint against requesting API keys or other credentials.
Audit Metadata