vision
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONPERSISTENCE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external project files to generate agent instructions and product documentation, creating a surface where malicious content in those files could influence agent behavior.
- Ingestion points: Project documentation files (
README.md,ARCHITECTURE.md,ROADMAP.md,CHANGELOG.md), configuration files (package.json,pyproject.toml,Cargo.toml), and project source code (entry points, services, routing table). - Boundary markers: None identified; the skill reads these files directly to extract product essence and principles.
- Capability inventory: File creation and modification (
docs/ux/vision.md,CLAUDE.md,AGENTS.md,GEMINI.md) and shell command execution (python3 docs/ux/lint.py). - Sanitization: None identified for the content extracted from project files before interpolation into the generated vision or rules.
- [COMMAND_EXECUTION]: The skill instructs the agent to execute a local Python script (
python3 docs/ux/lint.py) for validation. While the script is intended to be a local tool seeded by the skill pack, it represents a command execution capability. - [PERSISTENCE]: The skill modifies the agent's environment by injecting a 'Vision alignment — hard rule' into host-specific instruction files (
CLAUDE.md,AGENTS.md, orGEMINI.md). This modifies the agent's operational logic for all future sessions within the scope of the project.
Audit Metadata