scan-domain-entities

Pass

Audited by Gen Agent Trust Hub on Apr 10, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: No malicious patterns or behaviors were detected. The skill performs localized file reads and writes for documentation purposes and includes human-in-the-loop checkpoints for simple tasks.\n- [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection (Category 8) as it ingests untrusted codebase content during scanning. Ingestion points: Project source files and configurations scanned in Phase 2. Boundary markers: None explicitly defined in the scan instructions. Capability inventory: Reading project files and writing documentation to the docs/project-reference/ and plans/reports/ directories. Sanitization: None explicitly mentioned, though the structured output requirements (Mermaid diagrams and specific Markdown tables) significantly mitigate the risk of instruction execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 10, 2026, 07:25 AM