proj-gen
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill includes an 'Automatic Mode' that reads external technical scheme documents to extract table structures, entities, and interface information for code generation.
- Ingestion points: Reads project-specific technical scheme documents at paths retrieved from task documentation.
- Boundary markers: The instructions do not specify any delimiters or safety prompts to prevent the agent from following instructions that might be embedded within the technical documents instead of just data.
- Capability inventory: The skill has the capability to write multiple file types (SQL, Java Entity, Mapper, Service, Controller, DTO) to the local filesystem.
- Sanitization: There is no mention of sanitizing or validating the content of the technical documents before using them to populate code templates.
Audit Metadata