migration-guidance
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to run
pnpm api-diffto verify and generate migration documentation. This is a standard developer workflow for managing API changes and ensuring documentation matches code. - [INDIRECT_PROMPT_INJECTION]: The skill processes external configuration data which could theoretically contain malicious instructions.
- Ingestion points: Reads YAML annotation files located in
migration/annotations/(referenced in annotations.md). - Boundary markers: Relies on the YAML schema (replacement, note, example) to separate data fields.
- Capability inventory: Executes shell commands via
pnpmand performs file write operations tomigration/v3-to-v4.md(documented in generation.md). - Sanitization: The instructions explicitly mandate human-in-the-loop verification, requiring the agent to "Verify every suggested replacement against implementation and tests" and inspect generated output for anomalies.
Audit Metadata