scope
Pass
Audited by Gen Agent Trust Hub on Aug 21, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits a surface area for indirect prompt injection as it ingests untrusted data from multiple sources to influence its output and implementation actions.
- Ingestion points: Processes user input via interview phases, reads code repository content (files, history, tests), and scans
docs/wiki/for project context. - Boundary markers: While the instructions include a 'design confirmation' step to expose understanding bias, there are no explicit delimiters or system-level instructions to ignore embedded instructions within the ingested wiki or code files.
- Capability inventory: The skill can write documentation files to
docs/scope/and invoke thedo-scopedimplementation skill to perform code modifications based on gathered requirements. - Sanitization: No explicit sanitization, filtering, or escaping of external content is described before it is interpolated into implementation contracts or specifications.
Audit Metadata