ralph-specum-status
Pass
Audited by Gen Agent Trust Hub on Aug 20, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill aggregates data from local files, which creates a surface for indirect instructions.
- Ingestion points: Files including research.md, requirements.md, design.md, tasks.md, and .ralph-state.json are read from resolved roots (SKILL.md).
- Boundary markers: Absent; the instructions do not specify delimiters to separate untrusted file content from the system prompt.
- Capability inventory: Analysis of the skill body and referenced configurations shows only file-read and status aggregation capabilities; no network, file-write, or shell execution tools are present.
- Sanitization: Content is parsed for task completion counts and status flags but is not specifically sanitized against embedded instructions.
Audit Metadata