project-profile
Pass
Audited by Gen Agent Trust Hub on Aug 1, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by ingesting data from external sources to influence project configuration.
- Ingestion points: Processes configuration from a user-global file (~/.aidoc/profile.yaml) and accepts input via an interactive user interview.
- Boundary markers: The skill lacks explicit boundary markers or directives to ignore embedded instructions when writing the resulting .aidoc/profile.yaml file.
- Capability inventory: The skill is authorized to write to the local file system to maintain project profiles.
- Sanitization: The skill performs schema validation against a framework registry (ADAPTATION_SURFACE.yaml), filtering out keys not explicitly defined in the allowed surface.
- [NO_CODE]: The skill consists only of instructional content and markdown-based logic without accompanying executable scripts or binaries.
Audit Metadata