write-blueprint
Pass
Audited by Gen Agent Trust Hub on May 17, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill performs extensive codebase exploration, executing file-read operations on configuration files (e.g., pyproject.toml, package.json), lock files, and CI pipelines (e.g., GitHub Actions, GitLab CI) to discover project tooling.
- [COMMAND_EXECUTION]: Utilizes high-capability platform tools such as the 'Agent' tool to dispatch subagents for plan review and 'blueprints:execute-blueprint' for plan orchestration.
- [DATA_EXPOSURE]: Scans sensitive project areas including environment variables, configuration files, and data models to understand architecture and tooling requirements.
- [INDIRECT_PROMPT_INJECTION]: The skill has a surface for indirect prompt injection as it ingests untrusted data from both user requests and existing codebase files (which could contain malicious comments). This risk is mitigated by a multi-stage workflow requiring user confirmation of discovered tools, clarifying questions, and a mandatory adversarial review by a separate subagent.
Audit Metadata