3-build

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill is designed to execute shell commands for software implementation and verification tasks. These commands are extracted from the Build: and Verify (mechanical): fields of the checklist.md file. It also performs repository management tasks such as git init and automated git commit operations after each build step.
  • [INDIRECT_PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it reads and follows instructions found in project documentation (spec.md, prd.md) to generate its build plan and checklist.
  • Ingestion points: Processes data from docs/spec.md, docs/prd.md, docs/scope.md, and docs/checklist.md.
  • Boundary markers: The skill uses a rigid template with field labels (e.g., Build:, Commit:) to parse commands, which provides some structure but does not prevent the execution of malicious instructions embedded within those fields.
  • Capability inventory: Includes arbitrary shell command execution, Git repository modification, and file system writes.
  • Sanitization: There is no evidence of sanitization or validation for the commands derived from the documentation before they are executed in the shell.
  • [DYNAMIC_EXECUTION]: The skill operates by generating a checklist of tasks (including shell commands) and then systematically executing those tasks in a loop. This behavior effectively creates and executes a dynamic set of instructions at runtime based on the contents of the project's documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 04:36 PM
Security Audit — agent-trust-hub — 3-build