901-feature-loop

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes project source code, test files, and its own execution logs to drive automated development tasks. Malicious instructions embedded in these files could potentially influence the agent's behavior during its high-autonomy execution.
  • Ingestion points: Reads project source files, test files, and the implementation-log.jsonl state file.
  • Boundary markers: The skill does not define explicit delimiters or instructions to ignore embedded prompts within the processed files.
  • Capability inventory: Performs git operations (branch, commit, merge), file system writes, and subagent invocations (201, 202, 301, 302, 401, 402, 204).
  • Sanitization: No sanitization or validation of the content read from external project files is specified.
  • [COMMAND_EXECUTION]: The skill executes git commands (branch, commit, merge) directly via Bash based on the orchestration logic and outputs from other agents. While it includes a safety rule forbidding pushing to remotes, the automated execution of state-changing commands on the local repository increases the impact of potential logic errors or indirect injections.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 06:51 PM
Security Audit — agent-trust-hub — 901-feature-loop