aidlc-jump

Pass

Audited by Gen Agent Trust Hub on Oct 4, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes the engine orchestrate next command locally to advance the active workflow. This operation is limited to the functionality of the existing orchestrator tool.- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of user-provided arguments into a shell command, which is a common attack surface for indirect injection.
  • Ingestion points: User-provided inputs passed through the $ARGUMENTS variable in SKILL.md.
  • Boundary markers: None identified.
  • Capability inventory: Execution of system commands via the engine CLI.
  • Sanitization: The skill requires strict validation of input flags (--stage or --phase) before invoking the engine, effectively filtering non-compliant input.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 4, 2026, 07:24 PM
Security Audit — agent-trust-hub — aidlc-jump