source-command-fix-build

Pass

Audited by Gen Agent Trust Hub on Jun 23, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a standard software development workflow for fixing build errors. It includes clear constraints to ensure the agent only performs the minimum necessary changes to resolve a specific issue, which helps prevent unintended code modifications.
  • [PROMPT_INJECTION]: The skill processes untrusted data from build command outputs (stderr/stdout) to diagnose errors. While this constitutes an attack surface for indirect prompt injection, it is essential for the tool's primary purpose and no specific malicious intent was found.
  • Ingestion points: Full command failure output is ingested from the environment and passed to a sub-agent (defined in SKILL.md).
  • Boundary markers: Absent; the instructions do not specify the use of delimiters to isolate the command output from the sub-agent's instructions.
  • Capability inventory: The sub-agent (build-error-resolver) is authorized to analyze project configuration files and apply code diffs to fix identified errors.
  • Sanitization: No validation or sanitization of the command output is performed before it is analyzed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 23, 2026, 01:14 PM
Security Audit — agent-trust-hub — source-command-fix-build