start-work

Pass

Audited by Gen Agent Trust Hub on Aug 9, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes system-level tools including git for worktree and branch management, curl for verifying HTTP endpoints during QA, and node to execute local visual QA scripts.
  • [DATA_EXFILTRATION]: Includes mandatory 'evidence hygiene' rules that require the agent to redact or mask secrets, API keys, tokens, and PII before recording data in the ledger, pull request bodies, or handoff messages.
  • [EXTERNAL_DOWNLOADS]: Mentions the agent-browser repository from Vercel Labs' official GitHub organization as a fallback for browser-based verification.
  • [PROMPT_INJECTION]: The skill processes external plan files and project state which constitutes a surface for indirect prompt injection; however, it mitigates this risk by requiring 'Adversarial QA' gates to probe for common injection and manipulation patterns.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 9, 2026, 12:43 PM
Security Audit — agent-trust-hub — start-work