constraint-driven-development

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill defines and executes various shell commands for project linting, type checking, and security scanning (e.g., tsc, eslint, gitleaks, semgrep). It also includes a reference Node.js script that interacts with git to monitor changes in the repository to prevent the bypass of quality gates.\n- [EXTERNAL_DOWNLOADS]: The skill recommends installing several industry-standard development and security tools via official package managers, including npm, pip, and Homebrew. These include lighthouse, semgrep, gitleaks, and osv-scanner from well-known registries.\n- [INDIRECT_PROMPT_INJECTION]: The skill creates a CONSTRAINTS.md file that provides persistent instructions to the AI agent regarding project quality and safety standards. This is a core governance feature designed to prevent the agent from bypassing checks.\n
  • Ingestion points: Reads project configuration files (e.g., package.json, pyproject.toml) and user interview responses.\n
  • Boundary markers: The skill instructs the agent to update AGENTS.md or CLAUDE.md to explicitly reference CONSTRAINTS.md before writing code.\n
  • Capability inventory: The skill involves writing to the file system and executing security auditing tools.\n
  • Sanitization: Content is structured into a markdown contract format intended for agent guidance.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 11:34 PM
Security Audit — agent-trust-hub — constraint-driven-development