studio-develop-mvp-build
Pass
Audited by Gen Agent Trust Hub on Aug 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill treats
docs/ROADMAP.mdanddocs/PRD.mdas the source of truth for its actions, exposing it to malicious instructions embedded in these files. Ingestion points:docs/ROADMAP.md,docs/PRD.md,docs/DESIGN.md,docs/PRODUCT.md. Boundary markers: Absent. Capability inventory: File-write (implementation), Subprocess execution (verification steps), Network operations (git push). Sanitization: Absent. - [DYNAMIC_EXECUTION]: The skill is instructed to run verification steps and tests described in task notes, which involves executing code or commands that are dynamically defined in external files.
- [COMMAND_EXECUTION]: The work loop explicitly requires the agent to run verification commands for each task, which involves shell execution of untrusted content from the roadmap notes.
Audit Metadata