create-frontend-spec

Pass

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests and processes untrusted external data (such as Product Requirement Documents (PRDs), user research, or project briefs) to generate its output.
  • Ingestion points: Project context is gathered from external files (PRD, research) referenced in SKILL.md and the introduction section of front-end-spec-tmpl.yaml.
  • Boundary markers: The template lacks explicit boundary markers or instructions to the model to ignore malicious directives embedded within the processed external data.
  • Capability inventory: The skill utilizes the create-doc capability to write content to the filesystem (e.g., docs/front-end-spec.md).
  • Sanitization: No sanitization or validation logic is present to filter out instructions from the ingested documents before they are interpolated into the specification template.
Audit Metadata
Risk Level
SAFE
Analyzed
May 14, 2026, 07:01 AM
Security Audit — agent-trust-hub — create-frontend-spec