workflow-big-feature

Pass

Audited by Gen Agent Trust Hub on Apr 10, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security issues detected. The skill acts as a procedural orchestrator for a software development lifecycle.
  • [PROMPT_INJECTION]: The workflow involves processing untrusted data from web research and user prompts to drive code generation and planning.
  • Ingestion points: Data enters via the /web-research command and the initial user prompt provided to /workflow-start.
  • Boundary markers: The skill does not explicitly define delimiters for external data.
  • Capability inventory: The workflow includes high-capability tools such as /scaffold (file system modification) and /cook (code implementation).
  • Sanitization: Not specified within the skill instructions; the skill relies on the agent's native handling of tool outputs.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 10, 2026, 07:25 AM
Security Audit — agent-trust-hub — workflow-big-feature