estimate

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from task descriptions and project files, which could contain instructions designed to manipulate the agent.
  • Ingestion points: task-description argument and repository files such as CLAUDE.md, design/gdd/, and production/sprints/ (found in SKILL.md).
  • Boundary markers: The skill does not employ delimiters or instructions to ignore commands within the processed data.
  • Capability inventory: The skill is restricted to Read, Glob, and Grep tools and lacks network, file-write, or command execution capabilities.
  • Sanitization: No filtering or validation is applied to the ingested content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 06:52 PM
Security Audit — agent-trust-hub — estimate