recipe-marshal-json-config-audit

Pass

Audited by Gen Agent Trust Hub on Jul 11, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is a well-structured audit workflow that operates locally on project files. It does not perform network operations, exfiltrate data, or attempt to persist across sessions.
  • [COMMAND_EXECUTION]: The skill invokes project-specific management scripts (.plan/execute-script.py) via the Bash tool. These operations are restricted to status management and architecture discovery within the project's own directory.
  • [PROMPT_INJECTION]: While the skill ingests codebase data and configuration files, the risk of indirect prompt injection is mitigated by the structured execution flow and the requirement for explicit human approval via AskUserQuestion before any modifications are finalized.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 11, 2026, 07:12 AM
Security Audit — agent-trust-hub — recipe-marshal-json-config-audit