write-blueprint

Pass

Audited by Gen Agent Trust Hub on May 17, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill performs extensive codebase exploration, executing file-read operations on configuration files (e.g., pyproject.toml, package.json), lock files, and CI pipelines (e.g., GitHub Actions, GitLab CI) to discover project tooling.
  • [COMMAND_EXECUTION]: Utilizes high-capability platform tools such as the 'Agent' tool to dispatch subagents for plan review and 'blueprints:execute-blueprint' for plan orchestration.
  • [DATA_EXPOSURE]: Scans sensitive project areas including environment variables, configuration files, and data models to understand architecture and tooling requirements.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a surface for indirect prompt injection as it ingests untrusted data from both user requests and existing codebase files (which could contain malicious comments). This risk is mitigated by a multi-stage workflow requiring user confirmation of discovered tools, clarifying questions, and a mandatory adversarial review by a separate subagent.
Audit Metadata
Risk Level
SAFE
Analyzed
May 17, 2026, 02:09 PM
Security Audit — agent-trust-hub — write-blueprint