Define Core

Pass

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted user requests and external web search data (via Context7) to generate requirements documentation, which constitutes an indirect prompt injection surface.
  • Ingestion points: User requests and external documentation verified via Context7 WebSearch (as described in the investigate phase of SKILL.md).
  • Boundary markers: No explicit input delimiters are defined in the instructions, though output is managed via structured templates defined in the <output> section.
  • Capability inventory: All sub-agents (design, database, general-purpose, explore, validator) are explicitly configured as readonly="true". Rules DC-C001 and DC-C002 strictly prohibit file modifications and code implementation across all phases.
  • Sanitization: No explicit sanitization or filtering logic is implemented within the provided skill instructions.
  • [EXTERNAL_DOWNLOADS]: The workflow incorporates the Context7 tool and WebSearch capability to verify documentation and standard references. This involves network access to retrieve external data for fact-checking purposes during the investigate phase.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 13, 2026, 12:34 AM
Security Audit — agent-trust-hub — Define Core