00-andruia-consultant
Pass
Audited by Gen Agent Trust Hub on Jul 15, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests untrusted data from the local environment and user interviews to generate project plans.
- Ingestion points: The agent is instructed to perform an 'Escaneo Técnico' of existing code (e.g.,
package.json,src) and conduct user interviews ('Entrevista de Diagnóstico/Prescripción'). - Boundary markers: Absent. There are no explicit delimiters or instructions to ignore embedded commands within the scanned files or user responses.
- Capability inventory: The skill possesses file system read capabilities (to scan project structure) and file system write capabilities (to generate
tareas.mdandplan_implementacion.md). - Sanitization: None. The skill does not specify any filtering or validation for the content it reads before interpolating it into the final markdown artifacts.
Audit Metadata