project-specs
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because its core function involves processing and summarizing untrusted external data and repository files.
- Ingestion points: The skill is instructed to gather and research information from 'mentioned URLs', 'user notes', and 'existing code' (SKILL.md, Steps 1 and 4).
- Boundary markers: While the skill contains strong instructions to 'stop before build', it does not specify the use of delimiters or warnings to ignore instructions embedded within the research materials.
- Capability inventory: The skill has the capability to write multiple documentation files to the file system (SKILL.md). It is explicitly restricted from executing production code or refactors.
- Sanitization: No procedures for escaping or validating the content of external references or repository code are defined before they are incorporated into the project specifications.
Audit Metadata