implement
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided content from specification folders (
docs/specs/), including specifications, task lists, and visual prototypes, to drive its implementation logic. This creates a surface where instructions embedded in project data could influence agent behavior. - Ingestion points: The agent reads
spec.md, task files, and reference artifacts within the selected spec folder (SKILL.mdline 36). - Boundary markers: While the skill uses a 'reconciliation' phase to identify conflicts, it lacks explicit instructions to treat the external documentation as untrusted or to ignore embedded instructions.
- Capability inventory: The agent can write source code, execute shell commands for development servers and verification, and transmit data externally for review.
- Sanitization: No explicit sanitization or filtering of the ingested documentation is defined.
- [DATA_EXFILTRATION]: The skill implements a workflow for sending implementation diffs and specifications to external services (such as OpenAI) for automated code review. While this transmits project code to third-party infrastructure, it is managed as a core feature with clear user authorization guidelines.
- Evidence: The skill instructions emphasize identifying the service and the context being sent, carrying user authorization into the request, and forbidding the use of alternative tools to bypass security denials (
SKILL.mdlines 135-155).
Audit Metadata