shape-requirements

Pass

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill instructions and reference templates indicate the behavior is limited to user interaction and local file creation of markdown documentation. No patterns of prompt injection, data exfiltration, or unauthorized command execution were detected.
  • [PROMPT_INJECTION]: The skill processes untrusted user input and generates markdown briefs, creating a potential surface for indirect prompt injection. 1. Ingestion points: User input during requirement shaping in SKILL.md. 2. Boundary markers: The agent is instructed in references/interview-mode.md to synthesize prose rather than providing a raw transcript. 3. Capability inventory: File writing of markdown briefs as defined in references/brief-template.md. 4. Sanitization: No explicit sanitization of user input is performed before documentation. This finding is classified as safe as it represents the core intended functionality of the skill and the risk is contained to the generation of static data files.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 20, 2026, 04:20 AM
Security Audit — agent-trust-hub — shape-requirements