ai-prototyping

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes Python scripts prototype_plan.py and prototype_handoff_checker.py located in scripts/. These scripts are designed for local data processing and planning. Technical analysis of the source code confirms they use only standard Python libraries (json, argparse, re, sys, pathlib) and do not contain functions for arbitrary command execution, network communication, or subprocess invocation.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines an interface for processing user-supplied data in JSON and Markdown formats. While this presents an indirect injection surface, the skill implements a defense-in-depth approach by instructing users to treat generated content as untrusted and citing established security standards like OWASP LLM01:2025. It specifically mandates the use of synthetic data to prevent sensitive information from being processed by external AI tools.
  • [SAFE]: The skill includes a dedicated governance framework in references/testing-handoff-governance.md that addresses critical security vectors. It provides specific instructions to prevent hardcoding secrets or internal hostnames, requires legal review of tool terms, and enforces the archiving of prototype repositories. The documentation also mandates that any code generated during prototyping must undergo a full security review before being considered for production deployment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 08:34 PM
Security Audit — agent-trust-hub — ai-prototyping