create-epics-from-shards
Pass
Audited by Gen Agent Trust Hub on May 14, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it ingests and processes untrusted or external markdown content during the epic creation workflow.
- Ingestion points: The skill reads PRD shard files from the
docs/prd/directory in Step 1 and Step 3. - Boundary markers: Absent. There are no explicit instructions or delimiters used to separate the source shard content from the agent's system instructions or to warn the agent to ignore embedded commands.
- Capability inventory: The skill utilizes the agent's ability to read from and write to the local file system, specifically creating new files in the
epics/subdirectory and modifying the/docs/epic-registry.mdfile. - Sanitization: Absent. The workflow interpolates content extracted from the shards directly into epic templates without validation or sanitization steps to ensure the content does not contain executable directives.
Audit Metadata