game-ui-specification
Pass
Audited by Gen Agent Trust Hub on Aug 21, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill demonstrates an indirect prompt injection surface as it ingests project-specific data to influence its output.
- Ingestion points: The agent reads spec.md, research.md, and style-contract.yaml to extract design requirements.
- Boundary markers: The skill lacks explicit markers or instructions to treat data in these files as non-executable.
- Capability inventory: The agent has capabilities to read and write to the local file system.
- Sanitization: No sanitization or content validation is applied to the data retrieved from external files.
Audit Metadata