feature-implement

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to utilize repository-specific tooling, specifically Python scripts located in .claude/scripts/code_graph. These tools are used for static analysis, such as tracing code dependencies, blast radius, and caller/callee relationships during the implementation and investigation phases.
  • [PROMPT_INJECTION]: The instructions contain directives to prioritize the skill's specific protocol over platform-level mode-switch instructions and mandate strict adherence to the defined task order. This is a common pattern in complex AI agent workflows to prevent context drift and ensure procedural compliance.
  • [DATA_EXPOSURE]: The skill requires the agent to read internal project configuration and documentation files (e.g., docs/project-config.json, docs/project-reference/) to ground its actions in the project's specific conventions. This is standard behavior for repository-aware coding assistants.
  • [EXTERNAL_DOWNLOADS]: The skill references setup routines like $project-init or $sync-codex to be executed if project configuration is missing or stale. These are internal project commands and do not point to untrusted external sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 08:22 PM
Security Audit — agent-trust-hub — feature-implement