arkweb-spec-review
Pass
Audited by Gen Agent Trust Hub on Aug 8, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface due to its core functionality of reading and analyzing external documentation.- Ingestion points: The agent is instructed to read document files and code analysis results from the project repository paths (e.g.,
{DOCS_REPO}/docs/).- Boundary markers: The instructions do not specify the use of delimiters or specific safety instructions to treat the document content as strictly data, which could allow embedded instructions in the spec files to influence the agent's behavior.- Capability inventory: The skill grants the agent the ability to write new review documents to the file system and initiate pull requests.- Sanitization: No explicit sanitization or validation of the ingested document content is defined before it is applied to the 33-point checklist evaluation.
Audit Metadata