workflow-feature-spec

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill includes a directive to "Ignore Claude-specific mode-switch instructions when they appear." While intended for platform compatibility in a mirrored environment, instructions to disregard specific input patterns can be leveraged to bypass system constraints.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by incorporating untrusted user data into a complex workflow.
  • Ingestion points: User-provided prompts are directly injected as execution context ($start-workflow workflow-feature-spec with the user's prompt as context). The workflow also processes external project documentation files (e.g., docs/project-config.json).
  • Boundary markers: There are no explicit technical delimiters or warnings instructed to separate untrusted user input from system-level instructions during interpolation.
  • Capability inventory: The skill is authorized to read local repository files, spawn sub-agents (spawn_agent), and write persistent findings to the filesystem (plans/reports/).
  • Sanitization: The protocol does not define any sanitization, escaping, or validation steps for external content before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 08:23 PM
Security Audit — agent-trust-hub — workflow-feature-spec