phoenix-requirements-engineer

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns or security vulnerabilities were identified during the analysis of the skill instructions and metadata.
  • [PROMPT_INJECTION]: The instructions contain strict logical constraints, such as the requirement to follow RFC 2119 strictly and the prohibition of inventing facts. These constraints align with the skill's stated purpose and do not attempt to bypass agent safety filters or override system instructions.
  • [DATA_EXFILTRATION]: No network operations (such as curl, wget, or fetch), hardcoded credentials, or sensitive file path access (like .ssh or .aws) were detected. The skill operates on technical specification data within its own context.
  • [OBFUSCATION]: The content is written in clear text and does not utilize Base64 encoding, zero-width characters, homoglyphs, or other techniques to hide malicious intent.
  • [REMOTE_CODE_EXECUTION]: The skill does not download or execute external scripts, packages, or binary files. It focuses entirely on text transformation and documentation generation.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external scope definitions and constraint sets. While this presents an ingestion surface, the skill's capabilities are limited to generating markdown documentation and saving it to a local session path (outputs/{session-id}/), which does not provide a path for privilege escalation or remote execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 10:33 AM
Security Audit — agent-trust-hub — phoenix-requirements-engineer