generating-weaverse-project-json
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data from external sources, such as design specifications, website migration data, and verbal descriptions, to generate structured JSON exports. This creates an attack surface where malicious instructions embedded in the input data could potentially influence the agent's behavior.
- Ingestion points:
SKILL.mdidentifies several external inputs including section mappings from other skills, design specs, and verbal descriptions. - Boundary markers: The instructions do not mandate the use of delimiters or 'ignore' instructions to isolate the external data from the agent's primary instructions.
- Capability inventory: The skill leverages
python scripts/validate.py(documented inSKILL.md) to process and validate the generated file. - Sanitization: There are no instructions for sanitizing or escaping the external content before it is interpolated into the generation prompt.
- [COMMAND_EXECUTION]: The skill provides and instructs the agent to run a local Python validation script to ensure the generated JSON conforms to the required schema.
- Evidence:
SKILL.mdcontains the instruction:python scripts/validate.py <output-file>. The provided scriptscripts/validate.pyperforms structural and reference integrity checks on the JSON data.
Audit Metadata