feature-engineer

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill body and supporting files consist of instructional markdown and metadata. No executable scripts, network requests, or hardcoded credentials were found.
  • [PROMPT_INJECTION]: The skill processes untrusted external data (feature requests and codebase context) as part of its primary function, creating an indirect prompt injection surface. The instructions focus on engineering planning and implementation framing, which provides natural structure to the interaction.
  • Ingestion points: Feature requests, product goals, and user problems as defined in SKILL.md.
  • Boundary markers: The skill does not define specific delimiters or instructions to ignore embedded commands in input data.
  • Capability inventory: The instructions imply the agent has the capability to modify codebases and plan deployments, suggesting file system access.
  • Sanitization: No explicit input validation or sanitization requirements are provided for the agent to follow.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 11:46 AM
Security Audit — agent-trust-hub — feature-engineer