ubiquitous-language

Pass

Audited by Gen Agent Trust Hub on Aug 9, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill establishes a naming protocol for Domain-Driven Design (DDD) that prioritizes human decision-making over automated changes. The instructions are purely procedural and do not contain executable code, remote resource fetching, or credential handling.\n- [PROMPT_INJECTION]: The skill includes a surface for indirect prompt injection as it ingests domain terms from external YAML glossary files to guide code refactoring. This is documented according to the mandatory evidence chain:\n
  • Ingestion points: Domain terms and definitions are read from <context>.glossary.yml files located within the repository domain-scoped paths.\n
  • Boundary markers: The skill mandates a five-step protocol where the 'PROPOSE' step requires the agent to wait for human approval ('DECIDE') before applying changes.\n
  • Capability inventory: The agent performs text-based refactoring of code identifiers, test titles, and DSL verbs across the codebase.\n
  • Sanitization: Manual human review of all proposed vocabulary serves as the primary sanitization gate, preventing the automated execution of instructions that might be embedded in the glossary data.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 9, 2026, 03:06 PM
Security Audit — agent-trust-hub — ubiquitous-language