implement-and-review-loop
Pass
Audited by Gen Agent Trust Hub on Apr 5, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted data from specification files which serves as a surface for indirect prompt injection.
- Ingestion points: Reads requirements and task plans from Markdown files located in the
Docs/In-Progress/directory. - Boundary markers: The instructions do not specify the use of delimiters or 'ignore' instructions to isolate content from the processed specification files.
- Capability inventory: The workflow can execute shell commands (
git,gh,python3), modify the local filesystem, and initiate network-based deployment/PR tasks via delegated skills. - Sanitization: There is no explicit sanitization or validation logic for the text ingested from the specification documents before it is used to guide the agent's work.
- [COMMAND_EXECUTION]: The skill uses shell-based commands for validation and workflow automation.
- Evidence: Employs
python3 -cfor YAML syntax checking andsedfor line-based file inspection. - Validation: The Python command specifically uses
yaml.safe_load, which is the correct secure practice to prevent arbitrary code execution during YAML parsing. - Workflow: Uses
gitand the GitHub CLI (gh) for branching, committing, and pull request management as part of the standard development cycle.
Audit Metadata