specs-data
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes multiple external project files which could contain hidden instructions designed to influence the agent's analysis or output contents.\n
- Ingestion points: Technical specification files are read from
docs/specs/API/,docs/specs/data/,docs/specs/ws/,docs/specs/grpc/, anddocs/specs/task-UCS/.\n - Boundary markers: The instructions do not specify the use of delimiters or provide instructions to the model to ignore any embedded directives within the specification files being processed.\n
- Capability inventory: The skill is capable of performing file-write operations to
docs/specs/data/struct.mdbased on its analysis of external content.\n - Sanitization: There is no mechanism described for sanitizing or validating the contents of the specification files before they are summarized and integrated into the final document.
Audit Metadata