momentic-spec
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because its primary workflow involves reading and acting upon untrusted data from the user's repository.
- Ingestion points: Instructions in
SKILL.mddirect the agent to read repository guidance,momentic.config.yaml, and existing test/module files to inform its behavior. - Boundary markers: There are no defined delimiters or specific instructions to treat external file content as untrusted data or to ignore potential instructions embedded within those files.
- Capability inventory: The agent has the capability to modify repository files (both tests and product code), execute linting/unit tests, and invoke long-running end-to-end tests via the
momentic-testskill. - Sanitization: The skill lacks mechanisms to sanitize or validate ingested repository content before it is used to influence the agent's implementation or testing decisions.
Audit Metadata