tech-lead

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it is designed to ingest and process untrusted Product Requirement Documents (PRDs) during its audit phases.
  • Ingestion points: Phase 1 (SKILL.md) instructs the agent to audit the PRD provided by the user.
  • Boundary markers: The instructions lack explicit delimiters (e.g., XML tags or triple quotes) or warnings to the agent to treat the document content strictly as data.
  • Capability inventory: The skill is limited to generating text-based Technical Risk Reports and chaining to other assessment skills (review-prd, estimate-tasks).
  • Sanitization: No validation or sanitization of the input PRD text is performed before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 09:17 PM
Security Audit — agent-trust-hub — tech-lead