intent
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external data, specifically "pasted feedback or chat logs," which could contain malicious instructions designed to influence the agent's behavior during the intake process.
- Ingestion points: Data enters the agent context via the
argument-hintinput and the "contributor pastes raw feedback" workflow described in the Role Contract. - Boundary markers: The skill utilizes a structured five-section YAML+Markdown template (
intent.md) to categorize information, providing some structural delimitation. - Capability inventory: The skill is capable of drafting and writing local files to the
docs/intents/directory. - Sanitization: The primary defense mechanism is a human-in-the-loop process where a supervisor and product owner must manually verify and sign the intent before it is accepted.
Audit Metadata