estimate
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from task descriptions and project files, which could contain instructions designed to manipulate the agent.
- Ingestion points:
task-descriptionargument and repository files such asCLAUDE.md,design/gdd/, andproduction/sprints/(found in SKILL.md). - Boundary markers: The skill does not employ delimiters or instructions to ignore commands within the processed data.
- Capability inventory: The skill is restricted to
Read,Glob, andGreptools and lacks network, file-write, or command execution capabilities. - Sanitization: No filtering or validation is applied to the ingested content.
Audit Metadata