task
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes a natural language gap description to drive its implementation workflow, creating an attack surface where malicious instructions could be embedded in the task description to influence agent behavior. 1. Ingestion points: The /task command accepts a gap description as its primary input as described in SKILL.md. 2. Boundary markers: No explicit delimiters or warnings to ignore instructions within the gap description are present in the documentation. 3. Capability inventory: The skill can write source code and specs, execute tests via the TDD loop, manage workspaces (worktrees), and merge code to the production branch. 4. Sanitization: No input sanitization or validation mechanisms are described for the gap description.
- [DYNAMIC_EXECUTION]: The execution sequence involves a TDD loop that requires the agent to write and run tests and implementation code until passing. While this involves dynamic execution of agent-generated content, the skill incorporates a security gate through an adversarial review process requiring a clear verdict before final actions.
- [COMMAND_EXECUTION]: The skill uses git operations for isolation and lifecycle management, specifically mentioned as git worktree for workspaces and merging code back to the production branch upon completion.
Audit Metadata