nestjs-professional-software-engineering

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface because it is designed to ingest and process untrusted external data (project source code and requirements) while maintaining capabilities to modify the file system and execute CLI tools.
  • Ingestion points: Project source code, configuration files, and dependency manifests are read during the 'Inspect' and 'Understand' steps in SKILL.md.
  • Boundary markers: The skill defines a 'Pre-execution conflict guard' and 'Primary ownership' rules to manage cross-skill coordination and limit operational scope.
  • Capability inventory: The workflow facilitates file mutations during implementation and command execution for testing, linting, and building during the 'Test and verify' phase.
  • Sanitization: Implementation guidelines in SKILL.md explicitly mandate that the agent 'Validate untrusted input at boundaries and protect sensitive information.'
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 11:49 PM
Security Audit — agent-trust-hub — nestjs-professional-software-engineering