agentic-development
Pass
Audited by Gen Agent Trust Hub on Apr 12, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The 'scripts/repo_scan.py' script executes 'git' and 'ripgrep' shell commands to gather project metadata and identify tool usage.
- [EXTERNAL_DOWNLOADS]: The skill is configured to fetch guidelines from Vercel's public repository and incorporates animation libraries (GSAP, Lenis) from the jsDelivr CDN into generated front-end code.
- [COMMAND_EXECUTION]: The 'scripts/api_load_tester.py' tool enables the agent to perform automated HTTP requests against specified endpoints for performance verification.
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by instructing the agent to adopt rules and preferences from various repository-local files such as 'CLAUDE.md' or 'AGENTS.md', which could contain untrusted instructions.
Audit Metadata