feature-dev

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function involves reading and analyzing existing code from the user's codebase, which could contain malicious instructions designed to manipulate the agent's behavior. \n- Ingestion points: The agent reads files identified by sub-tasks in Phase 2 and Phase 5 as described in SKILL.md. \n- Boundary markers: The instructions do not specify the use of delimiters or protective prompts when processing external file content. \n- Capability inventory: The agent has capabilities to read files and write code to the local file system during the implementation phase (Phase 5). \n- Sanitization: No specific sanitization or validation logic is defined for the content extracted from the codebase.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:48 PM
Security Audit — agent-trust-hub — feature-dev