domain-model
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill operates by ingesting and analyzing content from the local codebase and documentation files, which constitutes a surface for indirect prompt injection if these files contain adversarial instructions.
- Ingestion points: Existing codebase files,
CONTEXT.md,CONTEXT-MAP.md, and files within thedocs/adr/directory are read to provide domain awareness. - Boundary markers: No specific delimiters or "ignore" instructions are provided to the agent regarding content found in the codebase.
- Capability inventory: The skill performs file reading (exploration) and file writing (updating
CONTEXT.mdand creating ADRs). - Sanitization: Content retrieved from the files is used directly to inform the agent's logic and documentation updates without explicit validation or sanitization rules.
Audit Metadata