ln-73-system-design-proposal-builder
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it ingests untrusted external data to drive its document generation and file-writing capabilities.\n- Ingestion points: The skill is designed to read 'Requirements and constraints', 'stakeholder input', and performs a 'Repository search' to gather context (SKILL.md).\n- Boundary markers: There are no instructions to use delimiters or ignore embedded instructions within the gathered external content.\n- Capability inventory: The agent possesses read access via repository search and write access through its 'Document mutation' and 'patch' instructions (SKILL.md).\n- Sanitization: No sanitization, validation, or escaping mechanisms are specified for the external data before it is interpolated into the agent's context or used to generate file patches.
Audit Metadata