design-spec

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data from Project Backlog Items (PBIs), user stories, and requirement documents to generate structured design specifications.
  • Ingestion points: Data enters the agent context through requirement text, user stories, and PBI content as described in the 'Workflow' and 'Input Routing' sections of SKILL.md.
  • Boundary markers: The protocol lacks explicit boundary markers or 'ignore' instructions to prevent the agent from following malicious commands that may be embedded within the input requirement text.
  • Capability inventory: The skill has the capability to write files to the team-artifacts/design-specs/ directory and perform visual analysis on uploaded images.
  • Sanitization: There are no documented sanitization or validation steps for the input text before it is interpolated into the design specification templates.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 02:36 AM
Security Audit — agent-trust-hub — design-spec