spec-workflow
Pass
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted information from web searches during its research phase, creating a surface for indirect prompt injection that can affect later stages of the workflow.\n
- Ingestion points: External web search results are used as primary input in the Research Phase (references/phase-transitions.md).\n
- Boundary markers: The skill documentation does not define specific delimiters or instructions to ignore commands within ingested data.\n
- Capability inventory: The agent possesses the capability to write files, perform git commits, and execute tasks autonomously (SKILL.md).\n
- Sanitization: There is no indication that data from the research phase is sanitized or validated before influencing task generation.\n- [COMMAND_EXECUTION]: The implementation phase relies on an autonomous agent to execute tasks and modify the codebase. Users should monitor these operations as they are based on dynamically generated content.
Audit Metadata