flow-shared
Pass
Audited by Gen Agent Trust Hub on Aug 17, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes external task descriptions within subagent prompts, creating a surface for indirect prompt injection.
- Ingestion points: The skill ingests untrusted task text into placeholders within
prompts/implementer.mdandprompts/reviewer.md. - Boundary markers: The prompts use Markdown headers to delimit task content, but do not include specific instructions for subagents to ignore potentially malicious commands embedded within the task text.
- Capability inventory: The subagents are granted capabilities to modify the filesystem, execute tests, and perform git operations such as
git commit. - Sanitization: The skill does not implement validation or sanitization of the task text before it is interpolated into prompts.
- [COMMAND_EXECUTION]: The skill orchestrates the use of standard development tools for workflow management.
- Evidence: The
references/execute-loop.mdandprompts/reviewer.mdinstructions require the agent to execute shell-based commands such asgit rev-parse HEADandgit diffto track changes and perform reviews.
Audit Metadata