cria-techspec
Pass
Audited by Gen Agent Trust Hub on Apr 5, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: Indirect Prompt Injection Surface. The skill processes data from user-provided PRD files (
tasks/prd-[feature-slug]/prd.md) to generate Technical Specifications. This creates a surface where adversarial instructions embedded within a PRD could attempt to override the agent's output format or behavior. - Ingestion points:
tasks/prd-[feature-slug]/prd.md(read in Step 2). - Boundary markers: Absent. Instructions require reading the file completely without explicit isolation.
- Capability inventory: File system read/write, Web Search, Context7 MCP tool execution.
- Sanitization: Absent. The skill does not perform validation or sanitization of the PRD content before processing.
- [COMMAND_EXECUTION]: Codebase Exploration. The "Deep Project Analysis" phase (Step 3) instructs the agent to perform comprehensive directory traversal and file reading to map symbols, dependencies, and integration points. This involves extensive access to the local file system to build an architectural map.
Audit Metadata