data-engineering-data-driven-feature
Pass
Audited by Gen Agent Trust Hub on Mar 5, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection due to the lack of input protection.
- Ingestion points: The $ARGUMENTS variable, representing user-provided feature requirements, is interpolated into sixteen distinct prompts across Phase 1 through Phase 6 in SKILL.md.
- Boundary markers: Absent. The instructions do not use delimiters or safety guidelines to isolate user input from the rest of the prompt content.
- Capability inventory: Targeted subagents (e.g., backend-architect, ml-engineer, deployment-engineer) have significant capabilities, including generating backend/frontend code and configuring cloud infrastructure.
- Sanitization: Absent. There is no evidence of validation or escaping performed on the user-provided data before it is processed by the orchestration logic.
Audit Metadata