interactive-requirements-gathering

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted user input through 'Type your own' options and uses this data to generate requirement documents, creating a potential surface for indirect prompt injection.
  • Ingestion points: User input received via the AskUserQuestion tool and specifically via 'Option D' (Type your own) as described in SKILL.md.
  • Boundary markers: No explicit instruction for the agent to use delimiters or sanitization for user-provided strings when interpolating them into generated requirements.
  • Capability inventory: The skill utilizes Read, Write, Edit, and AskUserQuestion tools across its operations.
  • Sanitization: No sanitization, escaping, or validation logic is defined for the custom user inputs before they are processed.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 09:05 PM
Security Audit — agent-trust-hub — interactive-requirements-gathering