xy-development

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest requirements from a PRD.md file and dynamically generate Layer 3 acceptance criteria, which the agent then uses to guide and verify its work through command execution and file manipulation.
  • Ingestion points: The workflow.md file specifies that the agent should read a PRD.md file at planning time to generate project-specific acceptance criteria.
  • Boundary markers: No explicit boundary markers or instructions to ignore embedded instructions within the PRD.md are provided to the agent.
  • Capability inventory: The skill empowers the agent to execute shell commands (pnpm build, pnpm test, pnpm lint, grep), perform file system operations, and use MCP browser tools (mcp__Claude_in_Chrome__*, mcp__Claude_Preview__*) for network-based verification.
  • Sanitization: There is no mention of sanitizing, escaping, or validating the content extracted from PRD.md before it is used to influence the agent's behavior and verification steps.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 10:32 PM
Security Audit — agent-trust-hub — xy-development