just-define
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill acts as an intermediary that processes user conversation to generate a persistent Manifest file at
~/.manifest-dev/manifests/. This creates a vulnerability surface where malicious instructions provided by a user during the 'interview' phase could be embedded into the resulting Manifest's Acceptance Criteria or Global Invariants, potentially influencing the behavior of downstream tools like/just-dothat execute these manifests. - Ingestion points: The skill ingests the entire conversation transcript and dynamic user responses during its 'interview' process to define the Manifest content.
- Boundary markers: The skill enforces a strict Markdown schema defined in
references/SCHEMA.mdand requires the inclusion of a specific 'ceiling invariant' to limit the scope of execution. - Capability inventory: The skill is capable of directory creation and file writing within the user's home directory (
SKILL.md). - Sanitization: No specific sanitization or filtering of the user-provided text is performed before it is encoded into the 'gate' texts of the Manifest.
Audit Metadata