requirements-delivery
Pass
Audited by Gen Agent Trust Hub on Aug 5, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it instructs the agent to process "source packages" that include external, untrusted data such as referenced documents and conversations.
- Ingestion points: The 'Requirement Sources' section in SKILL.md identifies user goals, requirements in any format, referenced documents, and conversations as primary inputs.
- Boundary markers: The skill does not define specific delimiters or instructions to prevent the agent from following malicious commands embedded within the source requirements.
- Capability inventory: The orchestrator and implementation agents are tasked with executing goals and delivering artifacts based on these requirements, which typically involves file system or environment modifications.
- Sanitization: There are no explicit requirements for the sanitization, validation, or escaping of ingested requirement data before processing.
Audit Metadata