maestro-blueprint

Pass

Audited by Gen Agent Trust Hub on Jul 12, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it ingests data from the local codebase and user arguments to inform its documentation phases.
  • Ingestion points: Project files accessed via Read, Glob, and Grep, user-supplied arguments, and local session files like blueprint-config.json.
  • Boundary markers: The instructions do not define specific delimiters or instructions for the agent to ignore embedded commands in the ingested data.
  • Capability inventory: The agent has access to Bash, file system modification tools (Write and Edit), and the ability to spawn subordinate agents (spawn_agents_on_csv).
  • Sanitization: There is no explicit description of sanitization or validation for external content.
  • [COMMAND_EXECUTION]: The skill utilizes the Bash tool and vendor-specific CLI utilities (maestro) to perform environmental analysis and state management. These commands are localized to the project environment and support the skill's primary function of documentation generation.
  • [DATA_EXFILTRATION]: Data access is confined to the local file system and relevant configuration paths. The skill enforces an output boundary, ensuring all generated artifacts are stored within the designated .workflow path, with no indicators of remote network exfiltration.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 12, 2026, 09:06 PM
Security Audit — agent-trust-hub — maestro-blueprint