slice
Pass
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill processes external input through the $ARGUMENTS variable (tracer-bullet card), which represents an indirect prompt injection surface.
- Ingestion points: Input section of SKILL.md.
- Boundary markers: No explicit delimiters are used to isolate the card data from instructions.
- Capability inventory: The skill directs the agent to perform code implementation, file changes, and project-specific slash commands.
- Sanitization: No sanitization is performed on the input card content. This is considered a surface for indirect instruction injection, although no malicious use is present in the skill itself.
- [SAFE]: The skill defines a professional software engineering process for implementing functional slices and does not contain hardcoded credentials, remote downloads, or obfuscated content.
Audit Metadata