requirement-assemble

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill demonstrates a surface for indirect prompt injection due to its position in an evidence-driven pipeline.
  • Ingestion points: The skill reads multiple upstream documents (e.g., 00-idea-intake.md through 10-acceptance.md) and research files in the research/ directory. These files are intended to contain 'external evidence' and findings from web searches.
  • Boundary markers: The templates provided in references/ use standard Markdown headers for structure, but do not implement specific boundary markers or 'ignore' instructions to isolate potentially malicious commands embedded in research data.
  • Capability inventory: The skill allows the agent to read and write files within the workspace and perform web searches based on a research plan.
  • Sanitization: There is no mention of sanitization or validation logic to filter out executable patterns or instructional overrides from the ingested documents before they are assembled into the final requirement file.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 05:07 PM
Security Audit — agent-trust-hub — requirement-assemble