feature-step

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill operates by ingesting and acting upon external data that could contain malicious instructions.
  • Ingestion points: Reads feature specifications, parent contracts, local instructions, repository code, and pull request content (SKILL.md).
  • Boundary markers: The skill instructions lack explicit markers or instructions to treat external data as untrusted or to ignore embedded natural language commands (SKILL.md).
  • Capability inventory: The agent is empowered to use repository tools, execute shell commands for testing and verification, and write code to the filesystem (SKILL.md).
  • Sanitization: There is no mention of sanitization or validation logic for the external content before it is processed or interpolated into the workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 06:21 AM
Security Audit — agent-trust-hub — feature-step