workflow-spec-sync
Pass
Audited by Gen Agent Trust Hub on Aug 24, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection by ingesting untrusted user prompts and repository documentation files.\n
- Ingestion points: Processes user-provided context and project reference files such as docs/project-config.json and docs/project-reference/* as specified in the Codex Project-Reference Loading section.\n
- Boundary markers: There are no explicit delimiters or 'ignore embedded instructions' warnings defined for the user-provided context within the SKILL.md file.\n
- Capability inventory: The skill allows spawning sub-agents (spawn_agent tool) and performs file operations including writing report files (plans/reports/*) and updating project specification and test documentation.\n
- Sanitization: The skill includes mandatory 'AI Mistake Prevention' and 'Critical Thinking Mindset' protocols that require file:line evidence for all claims and manual verification of generated content, which serves as a mitigation layer against malicious data processing.
Audit Metadata