tech-lead
Pass
Audited by Gen Agent Trust Hub on Aug 24, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it is designed to ingest and process untrusted Product Requirement Documents (PRDs) during its audit phases.
- Ingestion points: Phase 1 (SKILL.md) instructs the agent to audit the PRD provided by the user.
- Boundary markers: The instructions lack explicit delimiters (e.g., XML tags or triple quotes) or warnings to the agent to treat the document content strictly as data.
- Capability inventory: The skill is limited to generating text-based Technical Risk Reports and chaining to other assessment skills (review-prd, estimate-tasks).
- Sanitization: No validation or sanitization of the input PRD text is performed before it is processed by the agent.
Audit Metadata