design-define
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill represents a surface for indirect prompt injection as its primary function is to process untrusted data from project artifacts to generate documentation.
- Ingestion points: Instructions in
SKILL.mdandreferences/flow.mdspecify that content is extracted from User Stories (US-XXX), Technical Tasks (TK-XXX), and Work Items (WI-XXX). It also reads configuration from.agents/MEMORY.md. - Boundary markers: The instructions lack explicit directives for the agent to use delimiters or
Audit Metadata