business-analyst
Fail
Audited by Gen Agent Trust Hub on Feb 16, 2026
Risk Level: HIGHPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [Indirect Prompt Injection] (HIGH): The skill processes untrusted external content during the refinement of business ideas and user stories.
- Ingestion points: The
/refineand/storyworkflows read content fromidea-fileandpbi-filerespectively (SKILL.md). - Boundary markers: Absent. No delimiters or instructions are provided to the agent to treat this content as untrusted data.
- Capability inventory: The skill is permitted to use
Write,Edit, andTodoWritetools to modify the project environment. - Sanitization: Absent. There is no logic to filter or validate requirements before they are processed by the agent.
- [Dynamic Execution] (MEDIUM): File path construction for discovery operations relies on untrusted metadata.
- Evidence: The
Dynamic Module Discoverysection uses{frontmatter.domain_path}to construct paths forGlobandReadoperations. An attacker could provide a maliciousdomain_pathin an idea file to perform directory traversal or scan unauthorized parts of the file system.
Recommendations
- AI detected serious security threats
Audit Metadata