feature-manifest
Warn
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: MEDIUMOBFUSCATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [OBFUSCATION]: The file
SKILL.mdcontains the HTML entity<instead of the literal<character within a Bash command example:npm run feature:info -- <feature-id>. While this is likely a rendering artifact for documentation purposes, HTML entities are classified as a form of content obfuscation. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to read and process feature manifest files (YAML format) to validate project health and map features to code, creating a surface for indirect prompt injection.
- Ingestion points: The skill reads feature IDs and file paths from external manifest files during
npm run feature:infoandnpm run feature:validateoperations (SKILL.md). - Boundary markers: There are no explicit delimiters or instructions provided to the agent to ignore potentially malicious content embedded within the manifest fields.
- Capability inventory: The skill has access to
Bash(specificallynpmandnpxcommands),Read,Write, andEdittools as defined in the frontmatter (SKILL.md). - Sanitization: There is no evidence of validation or sanitization of the manifest content before it is processed by the underlying shell tools.
Audit Metadata