spec
Pass
Audited by Gen Agent Trust Hub on Mar 21, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: Indirect prompt injection surface identified through untrusted data processing.\n
- Ingestion points: Natural language requirements and PRD documents provided by users as described in the reasoning process.\n
- Boundary markers: The skill lacks explicit markers or instructions to isolate user-provided requirements from the agent's core instructions.\n
- Capability inventory: The agent is instructed to create and write YAML files to the filesystem (specifically within the tasks/ directory).\n
- Sanitization: No sanitization, escaping, or validation mechanisms are defined for the input text before it is incorporated into the generated specification files.
Audit Metadata