to-prd
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes content from decision record files that could contain instructions designed to override agent behavior.
- Ingestion points: It reads content from
.ai-workflow/work/<feature-slug>/decision-record.mdandshared/references/workflow-stage-routing.md. - Boundary markers: The skill lacks delimiters or specific instructions to treat ingested content as data rather than instructions.
- Capability inventory: Access is limited to reading and writing local markdown files within the project structure; no network or shell execution capabilities are present.
- Sanitization: Content from ingested files is used without escaping or validation.
Audit Metadata