rfi-preparer
Pass
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: Indirect Prompt Injection Surface
- Ingestion points: The skill reads project data from multiple JSON files, including plans-spatial.json, specs-quality.json, project-config.json, directory.json, rfi-log.json, submittal-log.json, and procurement-log.json (SKILL.md).
- Boundary markers: There are no explicit delimiters or instructions provided to the agent to ignore instructions embedded within these data sources.
- Capability inventory: The skill has the capability to write to project logs (rfi_log, submittal_log), draft emails, and generate HTML/PDF documents (SKILL.md, rfi-template.md, transmittal-template.md).
- Sanitization: There is no mention of sanitization or validation of the ingested data before it is transformed into formal technical language or populated into document templates.
Audit Metadata