four-core-documents
Pass
Audited by Gen Agent Trust Hub on Aug 12, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill performs expected business analysis and document generation tasks. It interacts only with project-specific files and uses authorized local tools for state management, following the intended functional design without security violations.- [INDIRECT_PROMPT_INJECTION]: The skill possesses a data ingestion surface as it reads from external market research and client input files. 1. Ingestion points: Data is sourced from
profile.json,stone-facts.json, and thepart-02-external-research/directory. 2. Boundary markers: The instructions do not specify the use of delimiters or 'ignore' warnings for external content. 3. Capability inventory: The skill has access toRead,Write,Edit, andBashtools. 4. Sanitization: No explicit sanitization or filtering logic is provided for the processed content. Despite these surface-level characteristics, the risk is considered negligible given the highly structured nature of the production methodology.- [COMMAND_EXECUTION]: The skill utilizes the Bash tool to execute local administrative scripts such asengagement-state.py. These operations are used for internal version control and project state updates, representing standard vendor functionality within the local workspace.
Audit Metadata