create-epics-from-shards

Pass

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it ingests and processes untrusted or external markdown content during the epic creation workflow.
  • Ingestion points: The skill reads PRD shard files from the docs/prd/ directory in Step 1 and Step 3.
  • Boundary markers: Absent. There are no explicit instructions or delimiters used to separate the source shard content from the agent's system instructions or to warn the agent to ignore embedded commands.
  • Capability inventory: The skill utilizes the agent's ability to read from and write to the local file system, specifically creating new files in the epics/ subdirectory and modifying the /docs/epic-registry.md file.
  • Sanitization: Absent. The workflow interpolates content extracted from the shards directly into epic templates without validation or sanitization steps to ensure the content does not contain executable directives.
Audit Metadata
Risk Level
SAFE
Analyzed
May 14, 2026, 07:01 AM
Security Audit — agent-trust-hub — create-epics-from-shards