feature-forge
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill functions by ingesting untrusted input from users during discovery interviews and codebase context via subagents to generate documents. The absence of specific boundary markers or sanitization logic for this external content represents a common vulnerability surface for indirect prompt injection.
- Ingestion points: User input elicited through the AskUserQuestions tool during discovery phases and technical data gathered by codebase analysis subagents (Task subagents).
- Boundary markers: The instructions do not define delimiters or specific 'ignore embedded instructions' warnings for the content being processed.
- Capability inventory: The skill has the capability to write to the file system to save generated specifications in markdown format.
- Sanitization: The skill lacks explicit instructions for validating, filtering, or escaping external content before it is incorporated into the output document.
Audit Metadata