domain-modeling
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: Analysis of the skill instructions and associated templates shows no malicious patterns. The tool performs standard documentation tasks and lacks dangerous capabilities such as network access or shell execution.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from documentation files (CONTEXT.md, CONTEXT-MAP.md, docs/adr/*.md) and project source code to build its context as described in SKILL.md. While explicit boundary markers and sanitization are absent, the skill's capabilities are restricted to writing or updating markdown documentation files and providing logical feedback. It lacks access to high-risk tools for network operations, sensitive system files, or arbitrary command execution, rendering the attack surface safe for its intended use.
Audit Metadata