blueprint

Pass

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill is designed to interact with the host system's CLI, specifically requiring 'git' and 'gh' (GitHub CLI) to automate the creation of branches, pull requests, and CI workflows as part of its execution plan.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it ingests and processes untrusted data from the local repository to generate its plans.
  • Ingestion points: Reads project structure, existing plans, and memory files from the local environment (file system).
  • Boundary markers: The skill does not explicitly define delimiters or specific 'ignore instructions' markers when reading external file content into its context.
  • Capability inventory: The skill possesses file-write capabilities (saving roadmaps to the 'plans/' directory) and execution capabilities for git and GitHub CLI tools.
  • Sanitization: There is no evidence of sanitization or validation of the ingested repository content before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 11, 2026, 03:41 AM
Security Audit — agent-trust-hub — blueprint