implement-spec
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and act upon external specifications and ticket data, which creates a vulnerability to indirect prompt injection.
- Ingestion points: The agent is instructed in
SKILL.mdto "Read the spec and tickets" to understand the implementation requirements. - Boundary markers: The instructions lack delimiters or explicit warnings to treat external content as data rather than instructions.
- Capability inventory: The agent has capabilities to create branches, manage git worktrees, perform merges, and interact with PRs.
- Sanitization: There is no mention of sanitizing or validating the contents of the specs or tickets before processing them.
Audit Metadata