skills/dzhng/skills/write-spec/Gen Agent Trust Hub

write-spec

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of untrusted data by instructing the agent to perform online research on external sources such as official documentation, source repositories, and research papers. This information is then used to prompt subagents during a parallel drafting process, creating a surface for indirect prompt injection.
  • Ingestion points: The "Research" step in the workflow explicitly directs the agent to fetch and process content from external URLs and primary sources.
  • Boundary markers: The skill does not define specific delimiters or "ignore embedded instructions" warnings when passing the results of external research to the subagents tasked with drafting implementation plans.
  • Capability inventory: The skill leverages the agent's capability to spawn multiple subagents and create HTML visualizations, which are potential execution or display vectors for injected content.
  • Sanitization: The skill relies on manual human review and cross-model synthesis rather than automated sanitization or filtering of external data retrieved during the research phase.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 02:52 AM
Security Audit — agent-trust-hub — write-spec