workflow-feature-spec
Pass
Audited by Gen Agent Trust Hub on Aug 24, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill includes a directive to "Ignore Claude-specific mode-switch instructions when they appear." While intended for platform compatibility in a mirrored environment, instructions to disregard specific input patterns can be leveraged to bypass system constraints.
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by incorporating untrusted user data into a complex workflow.
- Ingestion points: User-provided prompts are directly injected as execution context ($start-workflow workflow-feature-spec with the user's prompt as context). The workflow also processes external project documentation files (e.g., docs/project-config.json).
- Boundary markers: There are no explicit technical delimiters or warnings instructed to separate untrusted user input from system-level instructions during interpolation.
- Capability inventory: The skill is authorized to read local repository files, spawn sub-agents (spawn_agent), and write persistent findings to the filesystem (plans/reports/).
- Sanitization: The protocol does not define any sanitization, escaping, or validation steps for external content before it is processed by the agent.
Audit Metadata