skills/dafang/codestable/cs-feat-impl/Gen Agent Trust Hub

cs-feat-impl

Pass

Audited by Gen Agent Trust Hub on Jul 22, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill requires the execution of local utility scripts, such as .codestable/tools/codestable-worktree-gate.py, and standard project lifecycle commands including build scripts, linters, and test suites. These are used as gates to ensure code quality and integrity throughout the development process.\n- [PROMPT_INJECTION]: The skill has an indirect prompt injection surface inherent to its function of processing project-specific documentation.\n
  • Ingestion points: The agent reads instructions and context from files such as .codestable/attention.md, {slug}-design.md, {slug}-checklist.yaml, {slug}-review.md, and {slug}-qa.md.\n
  • Boundary markers: No specific technical delimiters are used to separate instructional content within these files from the agent's core logic.\n
  • Capability inventory: The agent is authorized to modify the project's source code and execute local shell commands for testing and validation.\n
  • Sanitization: The skill does not implement explicit sanitization or input validation for the data ingested from the project files, relying instead on the established development workflow and human review points.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 22, 2026, 12:38 PM
Security Audit — agent-trust-hub — cs-feat-impl