brainstorming
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [SAFE]: The skill defines a logical workflow for brainstorming and requirements gathering. It does not include any executable code, shell scripts, or external network requests. Findings indicate the skill is purely instructional markdown designed to guide agent behavior towards better design practices.\n- [INDIRECT_PROMPT_INJECTION]: The skill directs the agent to ingest external project data, which identifies a potential attack surface for indirect prompt injection common to agentic workflows.\n
- Ingestion points: The agent is instructed to read local files, documentation, and git commit history in SKILL.md.\n
- Boundary markers: There are no instructions in the skill to use delimiters or specific ignore rules for content found within project files.\n
- Capability inventory: The agent has the capability to write design documentation to the local filesystem and perform git commits, as outlined in the Checklist section of SKILL.md.\n
- Sanitization: The skill does not define any validation or sanitization for the data read from the project environment before it is processed by the model.
Audit Metadata