feature-manifest

Warn

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: MEDIUMOBFUSCATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [OBFUSCATION]: The file SKILL.md contains the HTML entity &lt; instead of the literal < character within a Bash command example: npm run feature:info -- &lt;feature-id>. While this is likely a rendering artifact for documentation purposes, HTML entities are classified as a form of content obfuscation.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to read and process feature manifest files (YAML format) to validate project health and map features to code, creating a surface for indirect prompt injection.
  • Ingestion points: The skill reads feature IDs and file paths from external manifest files during npm run feature:info and npm run feature:validate operations (SKILL.md).
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to ignore potentially malicious content embedded within the manifest fields.
  • Capability inventory: The skill has access to Bash (specifically npm and npx commands), Read, Write, and Edit tools as defined in the frontmatter (SKILL.md).
  • Sanitization: There is no evidence of validation or sanitization of the manifest content before it is processed by the underlying shell tools.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 23, 2026, 06:08 PM
Security Audit — agent-trust-hub — feature-manifest