00-andruia-consultant

Pass

Audited by Gen Agent Trust Hub on Jul 15, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests untrusted data from the local environment and user interviews to generate project plans.
  • Ingestion points: The agent is instructed to perform an 'Escaneo Técnico' of existing code (e.g., package.json, src) and conduct user interviews ('Entrevista de Diagnóstico/Prescripción').
  • Boundary markers: Absent. There are no explicit delimiters or instructions to ignore embedded commands within the scanned files or user responses.
  • Capability inventory: The skill possesses file system read capabilities (to scan project structure) and file system write capabilities (to generate tareas.md and plan_implementacion.md).
  • Sanitization: None. The skill does not specify any filtering or validation for the content it reads before interpolating it into the final markdown artifacts.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 15, 2026, 11:46 AM
Security Audit — agent-trust-hub — 00-andruia-consultant