generate-manifest
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- Indirect Prompt Injection Surface: The skill processes local files to generate metadata, creating a potential surface for indirect prompt injection if project documentation contains instructions intended for the agent. Ingestion points: project files like README.md, AGENTS.md, and source code. Boundary markers: specific instructions define how to infer fields and when to use placeholders. Capability inventory: the skill can write manifest.yaml to the filesystem and execute a local validation command. Sanitization: the process relies on mapping content to a predefined schema.
- Command Execution: The skill executes a validation command using a local tool. This is a functional requirement to ensure that the generated manifest meets repository standards before being finalized.
Audit Metadata