p-eng-feature
Pass
Audited by Gen Agent Trust Hub on Apr 16, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements a documentation-driven workflow for software architecture planning and does not execute arbitrary code or scripts.
- [PROMPT_INJECTION]: A surface for indirect prompt injection exists as the skill processes user-supplied feature requirements. 1. Ingestion points: User requirement inputs during Step 1. 2. Boundary markers: Absent. 3. Capability inventory: Writing documentation plans to the local './plans/' directory. 4. Sanitization: Absent. As the output is restricted to documentation files, the risk is negligible.
- [DATA_EXFILTRATION]: No network operations, credential harvesting, or sensitive data access patterns were identified.
- [COMMAND_EXECUTION]: The skill facilitates planning and delegation to other agents but does not perform any local shell execution or system modification itself.
Audit Metadata