living-documentation

Pass

Audited by Gen Agent Trust Hub on Mar 20, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Indirect Prompt Injection Surface.
  • Ingestion points: The skill processes content from .kiro/specs//requirements.md, .kiro/specs//design.md, and project source code files.
  • Boundary markers: No explicit markers or delimiters are present to distinguish untrusted file content from system instructions.
  • Capability inventory: The skill has the capability to write and update documentation files based on its analysis.
  • Sanitization: No validation or sanitization of the ingested content is performed before processing or writing to disk.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 20, 2026, 03:57 PM