claude-command-sdlc
Pass
Audited by Gen Agent Trust Hub on Jul 8, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow for processing 'planning packets', 'design contracts', and 'implementation artifacts' which are external/untrusted data inputs.
- Ingestion points: Data enters the agent context via 'planning packets' (Phase 1) and 'target files' (Phase 3).
- Boundary markers: No explicit instruction delimiters or 'ignore embedded instructions' warnings are present in the guidance files.
- Capability inventory: The skill orchestrates file creation (Phase 3), shell execution for 'smoke checks' and 'live invocations' (Phase 3/6), and configuration wiring (Phase 6).
- Sanitization: No explicit sanitization or validation of the ingested development artifacts is described in the reference materials.
Audit Metadata