sow-generator

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill contains an attack surface for indirect prompt injection through external data ingestion combined with tool execution capabilities.
  • Ingestion points: In SKILL.md and references/required-inputs.md, the workflow instructs the agent to gather project briefs from the user and conduct external research on the client via the WebSearch tool.
  • Boundary markers: There are no explicit delimiters or boundary markers specified to isolate the retrieved web content or user brief from the model's core instruction set.
  • Capability inventory: The skill is configured with access to Read, Write, Bash, and WebSearch tools, enabling it to write files (sow.md) and run system commands via shell execution.
  • Sanitization: No input verification or sanitization routines are implemented to clean or filter instructions that might be embedded within the project briefs or target client websites.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 01:02 PM
Security Audit — agent-trust-hub — sow-generator