implement

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill recommends using npx @ericrisco/rsc registry refresh to maintain the local skill registry. This utility is a vendor-owned resource associated with the skill author.
  • [COMMAND_EXECUTION]: The skill utilizes several local shell scripts to automate the software development lifecycle:
  • scripts/review-package: Orchestrates Git commands (git log, git diff) to bundle task changes for code review.
  • scripts/task-brief: Uses awk to parse and extract specific task blocks from markdown plan files.
  • scripts/sdd-workspace: Dynamically determines and manages a local scratch directory for temporary data storage.
  • [DYNAMIC_EXECUTION]: The core logic involves generating new code and immediately executing test suites (e.g., pytest, go test, vitest) to verify implementation. While this is the intended functionality, it involves the runtime execution of dynamically generated content.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and act upon external project documentation which could contain untrusted instructions.
  • Ingestion points: Reads specifications and plan files from 02-DOCS/wiki/sdd/specs/ and 02-DOCS/wiki/sdd/plans/ (SKILL.md).
  • Boundary markers: Requires explicit user approval of plans before implementation begins and adheres to a project constitution to define safety boundaries.
  • Capability inventory: File system modifications, Git repository management, and subagent dispatch for specialized tasks (SKILL.md, references/per-task-review.md).
  • Sanitization: Employs a 'per-task review gate' where a context-isolated subagent validates code compliance and quality against the original contract before completion.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 11:11 PM
Security Audit — agent-trust-hub — implement