creating-spec
Pass
Audited by Gen Agent Trust Hub on Mar 29, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill facilitates a workflow that ingests data from local source code and produces technical documentation, which introduces a surface for indirect prompt injection.\n
- Ingestion points: Phase 1 (Deep Exploration) instructs the agent to read across multiple codebases, including
providers/sdk,providers/runtime,packages/electron/src/agents/,packages/electron/src/looper/, andpackages/types.\n - Boundary markers: There are no instructions to use delimiters or ignore embedded instructions within the source files being analyzed.\n
- Capability inventory: The skill is designed to write comprehensive technical specifications to local files (e.g., in
tasks/prd-sdk/).\n - Sanitization: The instructions lack specific requirements for sanitizing or escaping the content retrieved from codebases before incorporating it into the final specification document.
Audit Metadata