next
Pass
Audited by Gen Agent Trust Hub on Jun 13, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill facilitates handoffs between agent contexts, which constitutes a multi-step prompt chain vulnerable to indirect injection.
- Ingestion points: Instructs the agent to read and summarize files such as design.md, plan.toml, and active phase sheets.
- Boundary markers: The skill does not provide instructions to wrap summarized content in protective delimiters or to ignore embedded commands within the artifacts.
- Capability inventory: The skill's primary function is text generation; it does not request or use tools for shell execution, file writing, or network access.
- Sanitization: There is no requirement for the agent to sanitize or validate the content of the project files before including it in the handoff prompt.
Audit Metadata