design-spec
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data from Project Backlog Items (PBIs), user stories, and requirement documents to generate structured design specifications.
- Ingestion points: Data enters the agent context through requirement text, user stories, and PBI content as described in the 'Workflow' and 'Input Routing' sections of SKILL.md.
- Boundary markers: The protocol lacks explicit boundary markers or 'ignore' instructions to prevent the agent from following malicious commands that may be embedded within the input requirement text.
- Capability inventory: The skill has the capability to write files to the
team-artifacts/design-specs/directory and perform visual analysis on uploaded images. - Sanitization: There are no documented sanitization or validation steps for the input text before it is interpolated into the design specification templates.
Audit Metadata