requirements-doc-gen
Pass
Audited by Gen Agent Trust Hub on Mar 16, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is designed to ingest and analyze user-provided 'rough descriptions' and existing documents. It lacks explicit safety boundaries or instructions to disregard potential commands embedded within these external inputs.
- Ingestion points: Processes user-provided text and uploaded documents in SKILL.md (Scenario 1 Step 1 and Scenario 2 Step 1).
- Boundary markers: Absent; there are no instructions to delimit user data or ignore embedded prompts.
- Capability inventory: Utilizes
web_searchto fetch external information (Scenario 1 Step 6). - Sanitization: Absent; no validation or filtering is applied to the content of processed documents.
Audit Metadata