develop
Pass
Audited by Gen Agent Trust Hub on May 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes various development tools via the shell, including
nxfor task orchestration, testing, and linting, andprismafor database migrations. It also runs a local bash script,advance-pipeline-lock.sh, to manage the state of the development pipeline. - [PROMPT_INJECTION]: The skill is subject to indirect prompt injection risks because it reads and processes external data (story/task markdown files and existing project source code) which directly informs its development decisions and command execution.
- Ingestion points: Consumes markdown documents (
story.*.md,task.*.md) and project source files discovered by theExploresubagent. - Boundary markers: Lacks explicit boundary markers or safety instructions to distinguish between the agent's instructions and potentially malicious content within the files it reads.
- Capability inventory: Possesses significant capabilities including shell command execution (
nx,prisma), file system modification, and git branch management. - Sanitization: Does not perform sanitization or validation of content ingested from the project files before utilizing it in prompts or implementation logic.
Audit Metadata