backend-implement

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill incorporates mandatory security and quality checks after code generation. Specifically, it uses pattern matching to detect raw SQL concatenation, which prevents SQL injection vulnerabilities, and ensures that business logic is properly isolated from transport and data access layers.
  • [COMMAND_EXECUTION]: The skill utilizes local shell commands like grep to perform static analysis on the project's source code. These commands are used solely for validating implementation rules (e.g., checking for raw SQL or framework leaks) and do not involve executing untrusted input or accessing sensitive system files.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface because it reads context from local project files (e.g., api-patterns.md, db-schema.md). While these files could theoretically contain malicious instructions, the skill's workflow is heavily constrained by structured code generation rules and mandatory validation checklists, which effectively mitigates the risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 10:46 AM
Security Audit — agent-trust-hub — backend-implement