creating-spec

Pass

Audited by Gen Agent Trust Hub on Mar 29, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill facilitates a workflow that ingests data from local source code and produces technical documentation, which introduces a surface for indirect prompt injection.\n
  • Ingestion points: Phase 1 (Deep Exploration) instructs the agent to read across multiple codebases, including providers/sdk, providers/runtime, packages/electron/src/agents/, packages/electron/src/looper/, and packages/types.\n
  • Boundary markers: There are no instructions to use delimiters or ignore embedded instructions within the source files being analyzed.\n
  • Capability inventory: The skill is designed to write comprehensive technical specifications to local files (e.g., in tasks/prd-sdk/).\n
  • Sanitization: The instructions lack specific requirements for sanitizing or escaping the content retrieved from codebases before incorporating it into the final specification document.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 29, 2026, 02:05 AM
Security Audit — agent-trust-hub — creating-spec