creating-spec

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill contains a vulnerability surface for indirect prompt injection because it processes untrusted data (source code) that could contain malicious instructions designed to subvert the agent's behavior.
  • Ingestion points: Phase 1 (Deep Exploration) instructs the agent to map the landscape and read key files directly from multiple codebases and shared packages.
  • Boundary markers: The instructions do not mandate the use of delimiters or specific blocks to encapsulate the read content, increasing the risk that the agent may interpret code comments or strings as instructions.
  • Capability inventory: The skill possesses the capability to write new technical specification files (Phase 3) and clarify design decisions with the user (Phase 2), which could be manipulated by injected instructions in the source files.
  • Sanitization: There is no evidence of sanitization or validation of the file content before it is used to generate the final specification document.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 11:03 PM
Security Audit — agent-trust-hub — creating-spec