sow-generator
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill contains an attack surface for indirect prompt injection through external data ingestion combined with tool execution capabilities.
- Ingestion points: In
SKILL.mdandreferences/required-inputs.md, the workflow instructs the agent to gather project briefs from the user and conduct external research on the client via theWebSearchtool. - Boundary markers: There are no explicit delimiters or boundary markers specified to isolate the retrieved web content or user brief from the model's core instruction set.
- Capability inventory: The skill is configured with access to
Read,Write,Bash, andWebSearchtools, enabling it to write files (sow.md) and run system commands via shell execution. - Sanitization: No input verification or sanitization routines are implemented to clean or filter instructions that might be embedded within the project briefs or target client websites.
Audit Metadata