domain-modeling
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied business terms and logic to update documentation files such as
CONTEXT.mdand Architecture Decision Records (ADRs). This represents an attack surface for indirect prompt injection if malicious instructions are persisted into the project's documentation. However, the risk is mitigated as the skill does not possess sensitive capabilities like network access or arbitrary command execution to act upon such instructions. - [NO_CODE]: The skill consists entirely of markdown instructions and formatting guides. It does not include any scripts, executable binaries, or configuration files that could facilitate malicious behavior at the system level.
Audit Metadata