docslime-fill
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's primary function involves reading and executing instructions embedded within
<!-- LLM: ... -->comments located in files under thedocs/directory. This creates an attack surface where a compromised or malicious template could influence the agent's behavior. - Ingestion points: The agent is instructed to open and read target files (e.g.,
docs/PRODUCT.md) to extract guidance comments. - Boundary markers: While the agent looks for specific
<!-- LLM: ... -->tags, the instructions do not include specific safeguards against adversarial content within those tags. - Capability inventory: The skill possesses the ability to read and write files within the local project structure and execute shell commands such as
grepfor verification. - Sanitization: The process relies on a human-in-the-loop interview format, but there is no explicit sanitization of the embedded template instructions before the agent interprets them.
Audit Metadata