intent-driven-development
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to 'Inspect context first' and perform an 'Existing Specification Review,' which involves reading local repository files, external documentation, and PRDs. This creates a surface for indirect prompt injection where malicious instructions embedded in these artifacts could influence the generated acceptance criteria or downstream agent actions.
- Ingestion points: The skill reads repository code, documentation, schemas, and user-supplied PRDs/specification documents (Step 2 and Step 3).
- Boundary markers: The skill does not define explicit delimiters or 'ignore' instructions for the content it processes, though it emphasizes treating repository facts differently from product constraints.
- Capability inventory: The skill enables analysis and definition of system behaviors based on ingested context but does not explicitly define subprocess or network capabilities itself.
- Sanitization: Rule 8 provides a mitigation by instructing the agent to redact real secrets, credentials, and personal data from its output.
Audit Metadata