runbook-writer

Pass

Audited by Gen Agent Trust Hub on Apr 5, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to Indirect Prompt Injection because it is designed to ingest and process content from external project documentation such as PRD, HLD, and LLD files. These documents are provided as context to sub-agents during the writing and review phases.
  • Ingestion points: Technical documents (PRD, HLD, LLD, API Contract, Guardrails) are read during Phase 0 and Phase 1 to build the context for the sub-agents.
  • Boundary markers: The prompt templates for the writer and reviewer sub-agents do not include explicit delimiters or 'ignore embedded instructions' warnings for the data interpolated from these documents.
  • Capability inventory: The skill has the capability to write and save files to the local file system (docs/runbook/[system-name]-runbook.md).
  • Sanitization: There is no explicit sanitization or filtering of the content extracted from the upstream documents before it is passed to the LLM-based sub-agents.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 5, 2026, 08:28 PM
Security Audit — agent-trust-hub — runbook-writer