develop-phase
Pass
Audited by Gen Agent Trust Hub on Aug 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements a logical software development lifecycle workflow. It does not contain any suspicious shell commands, network operations, or hardcoded credentials.
- [INDIRECT_PROMPT_INJECTION]: The skill has a data ingestion surface through the 'RESEARCH' and 'REVIEW' steps where it reads project specifications and codebase content.
- Ingestion points: Reads phase specifications and scans codebase files (SKILL.md).
- Boundary markers: The skill uses structured Markdown templates for reporting, which provides natural separation for agent outputs.
- Capability inventory: Uses standard agent capabilities for file reading, file modification, and testing.
- Sanitization: None explicitly defined in the workflow instructions, but the multi-step process with user checkpoints (Step 2.5) mitigates accidental obedience to embedded instructions.
Audit Metadata