orch-build-mvp

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes external design and specification documents (such as SDD or PRD files). These documents represent an untrusted input surface that could contain hidden instructions intended to override agent behavior or influence the generated code output.
  • Ingestion points: Processes document paths provided as arguments (e.g., civicpulse/docs/SDD-v0.6.md).
  • Boundary markers: The skill does not explicitly define delimiters or instructions to ignore embedded prompts within the source documents.
  • Capability inventory: The skill can scaffold code, execute build loops (/gan-build), and perform git commits.
  • Sanitization: No explicit sanitization or validation of the document content is mentioned before it is used to drive the build process.
  • [COMMAND_EXECUTION]: The skill invokes several orchestration commands and sub-processes, including /gan-build, gan-generator, and gan-evaluator. These tools are part of the local environment's orchestration framework and their behavior is directed by the contents of the processed specification documents.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:40 PM
Security Audit — agent-trust-hub — orch-build-mvp