requirement-engineering
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to explore project context by reading files, documents, and recent commits, which represents a surface for indirect prompt injection.
- Ingestion points: Instructions in
SKILL.mdto read local project files and git history. - Boundary markers: The instructions lack explicit delimiters or safety warnings to ignore instructions embedded within the files being read.
- Capability inventory: The skill performs file writes to the
.orchestration/directory and executes local shell commands. - Sanitization: The skill does not mention sanitizing or validating the content retrieved from the project context.
- [COMMAND_EXECUTION]: The skill executes a project-relative Node.js script
node scripts/orchestration/session.cjsto manage session initialization.
Audit Metadata