just-define

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill acts as an intermediary that processes user conversation to generate a persistent Manifest file at ~/.manifest-dev/manifests/. This creates a vulnerability surface where malicious instructions provided by a user during the 'interview' phase could be embedded into the resulting Manifest's Acceptance Criteria or Global Invariants, potentially influencing the behavior of downstream tools like /just-do that execute these manifests.
  • Ingestion points: The skill ingests the entire conversation transcript and dynamic user responses during its 'interview' process to define the Manifest content.
  • Boundary markers: The skill enforces a strict Markdown schema defined in references/SCHEMA.md and requires the inclusion of a specific 'ceiling invariant' to limit the scope of execution.
  • Capability inventory: The skill is capable of directory creation and file writing within the user's home directory (SKILL.md).
  • Sanitization: No specific sanitization or filtering of the user-provided text is performed before it is encoded into the 'gate' texts of the Manifest.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 08:34 PM
Security Audit — agent-trust-hub — just-define