backend-developer

Pass

Audited by Gen Agent Trust Hub on Aug 22, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill follows security best practices by explicitly instructing the agent to avoid hardcoding secrets and to treat all input as malicious until validated.- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data by reading user requests and project files to determine the technology stack. However, it implements safe boundary markers by strictly limiting its scope to specific reference files within the .agent/skills/ directory and using pre-defined paths. Capability inventory shows only standard documentation retrieval and code review functions. No unsafe interpolation or lack of sanitization was observed. Severity: SAFE.- [EXTERNAL_DOWNLOADS]: The skill mentions using search_web to consult official documentation when syntax is unknown. This is a standard functionality for an AI agent and follows the practice of relying on official documentation. Severity: SAFE.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 22, 2026, 01:18 PM
Security Audit — agent-trust-hub — backend-developer