brainstorm-beagle
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests and processes potentially untrusted content from the user's local workspace to generate specifications.
- Ingestion points: The skill reads project files, documentation, git history, and existing specifications during the 'Explore context' phase and the 'Prior Art Check' keyword sweep (SKILL.md).
- Boundary markers: There are no explicit instructions or delimiters used to separate the ingested workspace content from the system instructions or to warn the agent to ignore instructions embedded within the analyzed files.
- Capability inventory: The skill has the capability to write files to the
.beagle/concepts/directory, perform git commits, and potentially execute external research or analysis via tools likeweb-researchandartifact-analysis(SKILL.md). - Sanitization: The instructions do not specify any validation, filtering, or sanitization of the content read from the workspace before it influences the brainstorming dialogue or the final specification output.
- [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands, including
grep -riEfor workspace-wide capability searches andgit committo save the resulting spec documents to the repository (SKILL.md).
Audit Metadata