create-retro
Pass
Audited by Gen Agent Trust Hub on Mar 18, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes external documents and incorporates their content into generated reports without using boundary markers or sanitization. Ingestion points: Reads files from .chalk/docs/product/ and .chalk/docs/engineering/ (SKILL.md). Boundary markers: None. Capability inventory: Uses Read, Glob, Grep, and Write tools to manage documentation. Sanitization: No validation or filtering of content from external files is performed.
Audit Metadata