develop-phase

Pass

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a logical software development lifecycle workflow. It does not contain any suspicious shell commands, network operations, or hardcoded credentials.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a data ingestion surface through the 'RESEARCH' and 'REVIEW' steps where it reads project specifications and codebase content.
  • Ingestion points: Reads phase specifications and scans codebase files (SKILL.md).
  • Boundary markers: The skill uses structured Markdown templates for reporting, which provides natural separation for agent outputs.
  • Capability inventory: Uses standard agent capabilities for file reading, file modification, and testing.
  • Sanitization: None explicitly defined in the workflow instructions, but the multi-step process with user checkpoints (Step 2.5) mitigates accidental obedience to embedded instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 15, 2026, 11:27 PM
Security Audit — agent-trust-hub — develop-phase