intent-build-now
Pass
Audited by Gen Agent Trust Hub on Oct 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill relies on local specification documents (
INTENT.mdandplan.md) to drive its implementation and testing logic. If these files are maliciously crafted or contain unexpected instructions, they could influence the agent's behavior during the build process. - Ingestion points: The skill searches for and reads
INTENT.mdandplan.mdfrom the filesystem. - Boundary markers: There are no explicit delimiters or instructions defined to isolate the content of the specification files from the agent's core implementation instructions.
- Capability inventory: The skill has the capability to write code files, perform git commits, and execute shell commands (e.g., test scripts and E2E gates).
- Sanitization: No explicit sanitization or validation of the logic within the E2E Gate scripts or test cases is mentioned before execution.
- [COMMAND_EXECUTION]: The skill is designed to execute shell commands provided in the
plan.mdfile for testing and verification purposes. - Evidence: The skill explicitly mentions running E2E Gate scripts (e.g.,
pnpm test -- --grep "Phase 0") and executing TDD loops that involve running tests and writing implementation code based on file content.
Audit Metadata