swe-workflow

Pass

Audited by Gen Agent Trust Hub on Jun 14, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides a robust set of instructions and templates for managing complex coding tasks. It prioritizes evidence-based decision-making and surgical code changes. Analysis of the behavioral guards and core contract confirms the skill is focused on quality and structured output rather than harmful operations.- [PROMPT_INJECTION]: The skill facilitates the ingestion of data and instructions from the target repository being processed, which could contain adversarial content.
  • Ingestion points: references/command-discovery.md (scans repository files like package.json, Makefile, and AGENTS.md for executable commands) and references/require-clarification.md (instructs the agent to read the codebase to understand context).
  • Boundary markers: Absent. The skill does not explicitly instruct the agent to ignore or delimit instructions found within the repository files it reads.
  • Capability inventory: The agent has access to bash for command execution, read for file access, and write/edit for file modification across the entire repository.
  • Sanitization: None. The skill instructs the agent to 'discover' and 'record' commands from the repo but does not provide logic for validating the safety of these commands before execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 14, 2026, 01:59 AM
Security Audit — agent-trust-hub — swe-workflow