skills/google/capsem/dev-sprint/Gen Agent Trust Hub

dev-sprint

Pass

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • Data Ingestion Surface: The skill processes user-provided notes, goals, and task descriptions via the 'mcp__sprinty' toolset. This data ingestion is a standard feature for development tracking and serves as the primary mechanism for maintaining state across sessions.
  • Controlled Command Execution: The instructions explicitly direct the agent to run direct commands through a 'repository's bounded-command wrapper,' which is a security best practice to ensure operations remain within intended boundaries.
  • Security-Focused Development Lifecycle: The skill requires the inclusion of 'security acceptance work' and 'adversarial testing' evidence before closing tasks, promoting a secure and robust software development lifecycle.
  • Internal Resource Referencing: The skill references internal paths such as '/ironbank' for release-critical gates, indicating integration with a managed and potentially air-gapped security infrastructure.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 26, 2026, 06:45 PM
Security Audit — agent-trust-hub — dev-sprint