fstack-build

Pass

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill interprets and executes steps from an external file (PLAN.md), creating a surface for indirect prompt injection. If the plan is influenced by an untrusted source, the agent could be manipulated into performing unsafe actions.
  • Ingestion points: The agent reads tasks and logic directly from PLAN.md as defined in SKILL.md.
  • Boundary markers: The instructions assume the plan is 'approved' but do not define specific delimiters or instructions to ignore malicious directives embedded within the plan data.
  • Capability inventory: The skill has the capability to modify code and execute commands or tests as part of the implementation and verification steps.
  • Sanitization: The skill lacks automated sanitization or validation of the plan content, relying instead on manual human-in-the-loop verification and 'stop and ask' checkpoints.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 28, 2026, 09:37 AM
Security Audit — agent-trust-hub — fstack-build