engineering-senior-developer
Pass
Audited by Gen Agent Trust Hub on Mar 11, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes task lists provided by a Project Manager (PM) agent. This creates an indirect prompt injection surface where instructions embedded in task data could influence agent behavior. * Ingestion points: Task list from PM agent in SKILL.md. * Boundary markers: Absent; no specific delimiters defined for external input. * Capability inventory: Agent generates and implements web application code (Laravel, Livewire, CSS). * Sanitization: Absent; no validation or filtering of the task list is mentioned.
- [SAFE]: The skill follows standard patterns for defining an AI persona and references official documentation for FluxUI (fluxui.dev), a well-known technology service.
Audit Metadata