scan-domain-entities
Pass
Audited by Gen Agent Trust Hub on Apr 10, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: No malicious patterns or behaviors were detected. The skill performs localized file reads and writes for documentation purposes and includes human-in-the-loop checkpoints for simple tasks.\n- [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection (Category 8) as it ingests untrusted codebase content during scanning. Ingestion points: Project source files and configurations scanned in Phase 2. Boundary markers: None explicitly defined in the scan instructions. Capability inventory: Reading project files and writing documentation to the
docs/project-reference/andplans/reports/directories. Sanitization: None explicitly mentioned, though the structured output requirements (Mermaid diagrams and specific Markdown tables) significantly mitigate the risk of instruction execution.
Audit Metadata