software-engineer

Pass

Audited by Gen Agent Trust Hub on May 1, 2026

Risk Level: SAFE
Full Analysis
  • [DYNAMIC_CONTEXT_INJECTION]: The SKILL.md file utilizes the !command`` syntax (e.g., !cat .production-grade.yaml) to dynamically load project context and shared protocols into the agent's prompt during initialization. These shell commands are benign file-read operations used for context enrichment.
  • [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: The skill describes the installation of development dependencies via standard package managers (npm, pip, go mod, cargo) and uses a Makefile for local orchestration. These actions are standard for software engineering tasks and do not involve execution of untrusted remote code.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest architectural artifacts (OpenAPI specifications, database schemas). While this represents an attack surface for indirect instructions, the skill implements a structured, multi-phase development process with human-in-the-loop checkpoints (Phase 1 approval), which serves as a security control.
Audit Metadata
Risk Level
SAFE
Analyzed
May 1, 2026, 08:02 AM
Security Audit — agent-trust-hub — software-engineer