backend-dotnet-spec
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests decisions from a previous conversation flow (referred to as the 'grill') to generate documentation, which constitutes a surface for indirect prompt injection if that input data contains malicious instructions designed to influence the agent's output format or content.
- Ingestion points: Data is extracted from the
backend-dotnet-grillconversation history as referenced inSKILL.md. - Boundary markers: The instructions do not define delimiters or clear separation markers for the processed data to prevent instruction confusion.
- Capability inventory: The skill performs file system write operations to save the resulting specification file in the
specs/directory of the repository (SKILL.md). - Sanitization: There are no explicit instructions for sanitizing or validating the content gathered from the previous conversation before it is written to the file system.
Audit Metadata