tasks
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection as it ingests data from external project files to generate task lists. * Ingestion points: The skill reads architecture, requirements, and configuration data from several files, including
02-DOCS/wiki/sdd/plans/<slug>.md,02-DOCS/wiki/sdd/specs/<slug>.md,02-DOCS/wiki/sdd/constitution.md,02-DOCS/wiki/sdd/config.yaml, and02-DOCS/wiki/harness/user-profile.md. * Boundary markers: There are no explicit instructions or delimiters defined to isolate the content of these files or to instruct the model to ignore embedded malicious commands. * Capability inventory: The skill possesses the capability to modify local documents by appending task tables to the plan files and updating the02-DOCS/wiki/index.mdindex file. * Sanitization: The instructions do not specify any validation, escaping, or sanitization protocols for the data ingested from the project files before processing.
Audit Metadata