proj-gen

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill includes an 'Automatic Mode' that reads external technical scheme documents to extract table structures, entities, and interface information for code generation.
  • Ingestion points: Reads project-specific technical scheme documents at paths retrieved from task documentation.
  • Boundary markers: The instructions do not specify any delimiters or safety prompts to prevent the agent from following instructions that might be embedded within the technical documents instead of just data.
  • Capability inventory: The skill has the capability to write multiple file types (SQL, Java Entity, Mapper, Service, Controller, DTO) to the local filesystem.
  • Sanitization: There is no mention of sanitizing or validating the content of the technical documents before using them to populate code templates.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 10:08 AM
Security Audit — agent-trust-hub — proj-gen