software-engineer
Pass
Audited by Gen Agent Trust Hub on May 1, 2026
Risk Level: SAFE
Full Analysis
- [DYNAMIC_CONTEXT_INJECTION]: The
SKILL.mdfile utilizes the!command`` syntax (e.g.,!cat .production-grade.yaml) to dynamically load project context and shared protocols into the agent's prompt during initialization. These shell commands are benign file-read operations used for context enrichment. - [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: The skill describes the installation of development dependencies via standard package managers (npm, pip, go mod, cargo) and uses a
Makefilefor local orchestration. These actions are standard for software engineering tasks and do not involve execution of untrusted remote code. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest architectural artifacts (OpenAPI specifications, database schemas). While this represents an attack surface for indirect instructions, the skill implements a structured, multi-phase development process with human-in-the-loop checkpoints (Phase 1 approval), which serves as a security control.
Audit Metadata