backend-dev

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted user data, such as business requirements and technical constraints, to perform sensitive tasks including system architecture design and code generation. The instructions do not explicitly require the agent to use boundary markers or sanitization logic, which creates a potential surface for indirect prompt injection where malicious user input could attempt to influence the generated system's logic.
  • Ingestion points: User-provided business requirements and technical specifications ingested during the 'Requirements Analysis' phase.
  • Boundary markers: The skill does not provide delimiters or instructions for the agent to distinguish between user data and system instructions.
  • Capability inventory: The skill possesses the capability to generate production code, design database schemas, and configure CI/CD pipelines using integrated platform tools (/sc:design, /sc:implement, /sc:test).
  • Sanitization: No instructions are provided to the agent to validate or sanitize the external requirements before they are used to drive the implementation process.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 03:11 AM
Security Audit — agent-trust-hub — backend-dev