wachi-definicion
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted product descriptions and previous file versions to create structured contracts and update the product state machine.
- Ingestion points: The skill reads
fichero_inputand existing file content during Phase 1 to understand the product context. - Boundary markers: There are no explicit instructions to use delimiters or ignore potentially malicious content within these inputs.
- Capability inventory: The skill utilizes
guardar_ficha,actualizar_dor_ficha, andtransition_fichato persist data, update definitions of ready (DoR), and transition the product lifecycle status. - Sanitization: No validation or sanitization of the input data is mentioned before it is committed to the versioned product record.
Audit Metadata