spec
Pass
Audited by Gen Agent Trust Hub on Mar 10, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface.\n
- Ingestion points: Untrusted data is ingested through user-provided feature descriptions in $ARGUMENTS and codebase research using the Read, Glob, and Grep tools mentioned in SKILL.md.\n
- Boundary markers: Absent; the skill does not use delimiters or specific safety instructions to prevent the agent from following commands that might be embedded in the codebase or user input.\n
- Capability inventory: The skill has access to the Write tool for file system modification and lists the Task tool in its allowed tools, providing a surface for automated action based on injected content.\n
- Sanitization: No input validation, filtering, or escaping is performed on the ingested content before it is processed or written to the final specification file.
Audit Metadata