proj-analyze-req

Pass

Audited by Gen Agent Trust Hub on Apr 1, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is designed for the legitimate purpose of software requirement analysis. It utilizes local directories (docs/task and docs/req) for outputting documentation and task logs. No network exfiltration, hardcoded credentials, or unauthorized command executions were found.
  • [PROMPT_INJECTION]: The skill manages potential indirect prompt injection from user-provided requirements through a structured process. 1. Ingestion points: User requirement descriptions are ingested in Step 1. 2. Boundary markers: The skill uses a Step 0 task document and a Step 4 markdown template to structure inputs. 3. Capability inventory: The skill's capabilities are limited to writing documentation and interacting with the user. 4. Sanitization: The risk is mitigated by a mandatory clarification phase and a final user-confirmation checkpoint before any state transitions occur, ensuring the agent's understanding is verified by a human.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 1, 2026, 03:55 AM