to-issues
Pass
Audited by Gen Agent Trust Hub on Aug 5, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection through its primary data source.
- Ingestion points: The agent reads requirement documents from 'docs/01-Requirements/PRD-xxx.md' as defined in SKILL.md Step 1.
- Boundary markers: No explicit delimiters or instructions are provided to the agent to distinguish between data and potential commands within the PRD content.
- Capability inventory: The agent has the ability to read project files, write to '开发计划.md', and initiate the 'git-branch-plan' skill.
- Sanitization: There is no evidence of content filtering or sanitization before processing the PRD information.
Audit Metadata