migrate-breadcrumb-list

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to use local shell utilities like grep and wc to identify code patterns and monitor migration progress across the repository. It also prescribes the use of pnpm for running type checks and unit tests, as well as a local script .venv/bin/prek to validate the refactored code.
  • [INDIRECT_PROMPT_INJECTION]: The skill operates by ingesting and transforming local source code files (static/app). This creates an attack surface where malicious content embedded in the codebase (e.g., in comments or strings) could attempt to influence the agent's behavior. The risk is mitigated by the skill's highly specific transformation rules, reference implementations, and a detailed verification checklist that ensures the agent remains constrained to the migration task.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 06:57 AM
Security Audit — agent-trust-hub — migrate-breadcrumb-list