bs-requirements-engineering

Pass

Audited by Gen Agent Trust Hub on Jul 15, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill uses 'HARD RULES' and a 'Refusal Protocol' to prevent the agent from skipping steps even if requested by the user. While this is an instruction override, it is functionally limited to enforcing the requirements engineering methodology and does not attempt to bypass platform safety filters or administrative controls.
  • [INDIRECT_PROMPT_INJECTION]: The skill represents an ingestion surface for untrusted data in 'Stage 1' and 'Stage 2', where it processes user prompts and external documents (PRDs, RFCs) to detect gaps and synthesize requirements.
  • Ingestion points: Stage 1B (Raw Intent Capture) and Input Triage (Structured documents).
  • Boundary markers: None explicitly defined for delimiters, though the skill relies on iterative user confirmation ('Hard Gates') to validate interpreted content.
  • Capability inventory: The skill uses AskUserQuestion and provides instructions to hand off context to other skills like spec-writing or system-design upon approval.
  • Sanitization: The pipeline requires explicit user confirmation at multiple 'Hard Gates' before proceeding, providing a human-in-the-loop verification of all synthesized data.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 15, 2026, 03:30 AM
Security Audit — agent-trust-hub — bs-requirements-engineering