full-stack-master
Pass
Audited by Gen Agent Trust Hub on Mar 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The workflow executes standard local shell commands including
pnpm lint,pnpm typecheck, andpnpm testto perform code quality and functional validation during the 'Quality Detection' phase.- [EXTERNAL_DOWNLOADS]: The use ofpnpmimplies interaction with official package registries (such as npmjs.org) for managing and installing project dependencies.- [DATA_EXPOSURE]: The skill has an indirect prompt injection surface as it ingests untrusted user requirements and interview responses (SKILL.md) while possessing file-writing capabilities through referenced sub-skills (e.g., code-editor) and command execution capabilities (e.g., quality-guardian); however, this is inherent to the agent's primary purpose and no specific malicious exploitation patterns are present.
Audit Metadata