writing-product-specs
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied information to generate product specifications, which creates an attack surface for indirect prompt injection.
- Ingestion points: User input provided during Step 1 (Understand the Requested Feature or Project) is used to populate the specification template.
- Boundary markers: The instructions do not define specific delimiters or warnings for the agent to distinguish between user-provided data and agent instructions.
- Capability inventory: The skill is capable of writing and saving markdown file artifacts to the local workspace.
- Sanitization: No sanitization or validation of user input is specified before interpolation into the final document.
Audit Metadata