requirements-analyst
Fail
Audited by Gen Agent Trust Hub on Feb 16, 2026
Risk Level: HIGH
Full Analysis
- [SAFE] (SAFE): No active threats or malicious patterns identified in the skill files.- [EXTERNAL_DOWNLOADS] (LOW): An automated scan alert referenced a malicious URL in a missing file 'requirements.md'; however, this file is not part of the provided skill set, and no external links or download commands exist in the analyzed files.- [PROMPT_INJECTION] (LOW): The content uses instructional language regarding a 'Constitutional mandate' for requirement formatting; this is assessed as a domain-specific instruction rather than an attempt to override AI safety filters.- [INDIRECT_PROMPT_INJECTION] (LOW): The skill is designed to process untrusted external data (software requirements). Mandatory Evidence Chain: 1. Ingestion Point: Requirement text processed by validation functions in 'validation-rules.md'. 2. Boundary Markers: None present. 3. Capability Inventory: No subprocess execution, file-writing, or network operations detected. 4. Sanitization: None. The severity remains LOW because the skill only provides internal reasoning and formatting feedback without side-effect capabilities.
Recommendations
- Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata