demo
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes existing files and documentation from the local environment to inform its product analysis and generation process.
- Ingestion points: Accesses the local file system and existing documents during Phase 1 to establish product context.
- Capability inventory: The skill is capable of performing web searches using
WebSearch, creating directories via shell, and writing Markdown, HTML, CSS, and JavaScript files to the project directory. - Boundary markers: While it categorizes findings as facts, hypotheses, or pending items, it lacks explicit delimiters or instructions to disregard potential commands embedded within the documents it reads.
- Sanitization: There are no specific instructions to sanitize or escape data extracted from the environment before using it to generate documentation or code, which could lead to instructions in those documents influencing the agent's behavior.
Audit Metadata