build-feature

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill functions as a driver for complex feature development, ingesting user requirements and delegating tasks to subagents. It implements robust boundary markers in the form of two mandatory human approval checkpoints—one for the design specification and one for the implementation plan/DAG—before any code generation occurs. This ensures that the agent's capabilities (file writing, subagent spawning, and Git operations) are exercised only under explicit user supervision, mitigating the risk of instructions in untrusted data being executed without oversight.
  • [DYNAMIC_EXECUTION]: The skill manages the dynamic spawning and parallel execution of subagents. Each subagent is restricted to a specific scope (file list and task definition) and is instructed to load quality-enforcement skills such as 'typescript-standards' and 'test-hygiene'. The execution state is monitored via a JSON tracking file and visualized through Mermaid diagrams, providing transparency into the process.
  • [SAFE]: The skill includes explicit instructions to avoid committing temporary planning artifacts to version control and routes failures to a dedicated fix-bug workflow, demonstrating a defensive design posture aimed at maintaining repository integrity.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 07:40 PM
Security Audit — agent-trust-hub — build-feature