rank
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external data (lists of features, tasks, or backlog items) during its prioritization workflow.
- Ingestion points: Data enters the agent's context through user-provided item lists or backlog descriptions during the
COLLECTphase defined inSKILL.md. - Boundary markers: No explicit delimiters or instructions are provided to the agent to treat item names as untrusted content, which could lead to confusion if an item name contains instructions.
- Capability inventory: The skill has no access to dangerous tools. Its primary function is to generate text reports and log actions. It does not execute code, perform network operations, or modify sensitive files.
- Sanitization: There are no explicit validation or escaping procedures defined for the input items.
- [EXTERNAL_DOWNLOADS]: The documentation references external methodological resources from well-known platforms including academic repositories (arXiv), scientific journals (Nature), and established industry blogs (Intercom, Scaled Agile). These are provided for methodology calibration and do not involve remote code execution.
Audit Metadata