context-engineer

Pass

Audited by Gen Agent Trust Hub on May 3, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface as it is designed to ingest and package external project data for downstream agents. This is an inherent part of its functionality as a context management tool.\n
  • Ingestion points: The skill reads data from codebase files, .spec.md, and DESIGN.md.\n
  • Boundary markers: None explicitly defined in the inject action instructions to separate user content from system instructions.\n
  • Capability inventory: The skill has the capability to write to .claude/context-payload.md and depends on a shell hook (ralph-subagent-start.sh) to deliver context to sub-agents.\n
  • Sanitization: The skill does not describe any sanitization or validation of the ingested content before it is passed to other agents.
Audit Metadata
Risk Level
SAFE
Analyzed
May 3, 2026, 11:06 AM