intent-driven-development

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to 'Inspect context first' and perform an 'Existing Specification Review,' which involves reading local repository files, external documentation, and PRDs. This creates a surface for indirect prompt injection where malicious instructions embedded in these artifacts could influence the generated acceptance criteria or downstream agent actions.
  • Ingestion points: The skill reads repository code, documentation, schemas, and user-supplied PRDs/specification documents (Step 2 and Step 3).
  • Boundary markers: The skill does not define explicit delimiters or 'ignore' instructions for the content it processes, though it emphasizes treating repository facts differently from product constraints.
  • Capability inventory: The skill enables analysis and definition of system behaviors based on ingested context but does not explicitly define subprocess or network capabilities itself.
  • Sanitization: Rule 8 provides a mitigation by instructing the agent to redact real secrets, credentials, and personal data from its output.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:40 PM
Security Audit — agent-trust-hub — intent-driven-development