implement
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes repository-provided instructions, 'intent' documents, and 'check recipes' which could theoretically contain malicious instructions designed to subvert agent actions during implementation or verification tasks.
- Ingestion points: The skill reads repository-specific content including intent, acceptance criteria, and build/test recipes as described in
SKILL.md(Workflow Steps 1 & 4) andreferences/operations.md. - Boundary markers: The instructions do not define specific delimiters or security warnings when handling these external repository inputs.
- Capability inventory: The skill possesses the capability to execute shell commands for building, testing, and linting projects in various languages (Go, Python, Node, Rust) and performs file system writes during scaffolding, as detailed in
references/scaffold/generic-templates.md. - Sanitization: There is no explicit requirement to sanitize or validate the content of the 'check recipes' or 'intents' before the agent acts upon them.
- [COMMAND_EXECUTION]: The skill instructions direct the agent to run various build, test, and linting commands (e.g.,
go test,python -m pytest,cargo build,npx vitest) to verify implementation changes and scaffolds. While these are standard development tasks, they involve executing logic defined within the repository's configuration files (like Makefiles or CI scripts).
Audit Metadata