aidlc-outcomes-pack

Pass

Audited by Gen Agent Trust Hub on Oct 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the workspace to generate a summary report, creating a potential surface for indirect prompt injection.
  • Ingestion points: In SKILL.md, Step 2 specifies reading 'All artefacts recursively under //' and 'The delivered application and infrastructure code at the workspace root.'
  • Boundary markers: No specific delimiters or 'ignore' instructions are provided to the agent to distinguish between data and potential instructions within the source files.
  • Capability inventory: The skill executes local commands via {{INVOKE}} engine runtime summary and performs file writes to OUTCOMES.md.
  • Sanitization: There is no evidence of sanitization, escaping, or validation of the content read from the workspace before it is processed by the agent.
  • [COMMAND_EXECUTION]: The skill invokes the engine runtime summary --json command to gather workflow statistics using the platform's tool invocation syntax.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 4, 2026, 07:24 PM
Security Audit — agent-trust-hub — aidlc-outcomes-pack