ai-prototyping
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill includes Python scripts
prototype_plan.pyandprototype_handoff_checker.pylocated inscripts/. These scripts are designed for local data processing and planning. Technical analysis of the source code confirms they use only standard Python libraries (json, argparse, re, sys, pathlib) and do not contain functions for arbitrary command execution, network communication, or subprocess invocation. - [INDIRECT_PROMPT_INJECTION]: The skill defines an interface for processing user-supplied data in JSON and Markdown formats. While this presents an indirect injection surface, the skill implements a defense-in-depth approach by instructing users to treat generated content as untrusted and citing established security standards like OWASP LLM01:2025. It specifically mandates the use of synthetic data to prevent sensitive information from being processed by external AI tools.
- [SAFE]: The skill includes a dedicated governance framework in
references/testing-handoff-governance.mdthat addresses critical security vectors. It provides specific instructions to prevent hardcoding secrets or internal hostnames, requires legal review of tool terms, and enforces the archiving of prototype repositories. The documentation also mandates that any code generated during prototyping must undergo a full security review before being considered for production deployment.
Audit Metadata