5-build

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill demonstrates safe behavior by implementing robust secret scanning and following a learner-led process. No malicious patterns were identified.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from project documentation files to perform code generation and command execution.\n
  • Ingestion points: Documentation files in the devpost/ directory including spec.md and prd.md.\n
  • Boundary markers: The instructions do not specify the use of delimiters when processing documentation content.\n
  • Capability inventory: The agent performs file writes, git operations, and shell command execution for build verification.\n
  • Sanitization: Code snippets are escaped when generating the application map to prevent executable content injection.\n- [COMMAND_EXECUTION]: The skill uses the command line to perform git operations and verify build steps.\n- [DYNAMIC_EXECUTION]: The skill generates source code based on project specifications provided by the user.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 03:18 PM
Security Audit — agent-trust-hub — 5-build