define-domain-language
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses a
grepcommand to scan the local filesystem (specificallylib/andapp/directories) for Ruby class and module definitions. This is a legitimate functional requirement for extracting existing domain terms from the codebase. - [INDIRECT_PROMPT_INJECTION]: The skill processes content from local source files via
grep. This creates an ingestion point for untrusted data if the project code contains malicious comments or strings. - Ingestion points: Local Ruby files in
lib/andapp/viagrepinSKILL.md. - Boundary markers: None explicitly defined for the search output.
- Capability inventory: Uses
grepfor file system read operations. - Sanitization: None performed on the extracted class/module names.
Audit Metadata