claude-command-sdlc

Pass

Audited by Gen Agent Trust Hub on Jul 8, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow for processing 'planning packets', 'design contracts', and 'implementation artifacts' which are external/untrusted data inputs.
  • Ingestion points: Data enters the agent context via 'planning packets' (Phase 1) and 'target files' (Phase 3).
  • Boundary markers: No explicit instruction delimiters or 'ignore embedded instructions' warnings are present in the guidance files.
  • Capability inventory: The skill orchestrates file creation (Phase 3), shell execution for 'smoke checks' and 'live invocations' (Phase 3/6), and configuration wiring (Phase 6).
  • Sanitization: No explicit sanitization or validation of the ingested development artifacts is described in the reference materials.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 8, 2026, 04:17 PM
Security Audit — agent-trust-hub — claude-command-sdlc