3-build
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill is designed to execute shell commands for software implementation and verification tasks. These commands are extracted from the
Build:andVerify (mechanical):fields of thechecklist.mdfile. It also performs repository management tasks such asgit initand automatedgit commitoperations after each build step. - [INDIRECT_PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it reads and follows instructions found in project documentation (
spec.md,prd.md) to generate its build plan and checklist. - Ingestion points: Processes data from
docs/spec.md,docs/prd.md,docs/scope.md, anddocs/checklist.md. - Boundary markers: The skill uses a rigid template with field labels (e.g.,
Build:,Commit:) to parse commands, which provides some structure but does not prevent the execution of malicious instructions embedded within those fields. - Capability inventory: Includes arbitrary shell command execution, Git repository modification, and file system writes.
- Sanitization: There is no evidence of sanitization or validation for the commands derived from the documentation before they are executed in the shell.
- [DYNAMIC_EXECUTION]: The skill operates by generating a checklist of tasks (including shell commands) and then systematically executing those tasks in a loop. This behavior effectively creates and executes a dynamic set of instructions at runtime based on the contents of the project's documentation.
Audit Metadata