migrate-breadcrumb-list
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to use local shell utilities like
grepandwcto identify code patterns and monitor migration progress across the repository. It also prescribes the use ofpnpmfor running type checks and unit tests, as well as a local script.venv/bin/prekto validate the refactored code. - [INDIRECT_PROMPT_INJECTION]: The skill operates by ingesting and transforming local source code files (
static/app). This creates an attack surface where malicious content embedded in the codebase (e.g., in comments or strings) could attempt to influence the agent's behavior. The risk is mitigated by the skill's highly specific transformation rules, reference implementations, and a detailed verification checklist that ensures the agent remains constrained to the migration task.
Audit Metadata