fullstack-dev

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions for the agent to execute shell commands such as npm run build and curl to verify application health and build status in the local development environment. These commands are standard for the described development workflow.
  • [INDIRECT_PROMPT_INJECTION]: The skill implements a workflow that gathers user-provided requirements to influence code generation and local command execution. This creates a surface where malicious instructions could be embedded in the requirements to manipulate the agent's output or actions.
  • Ingestion points: User-provided requirements gathered during the requirement gathering phase in Step 0 (SKILL.md).
  • Boundary markers: No explicit boundary markers or delimiters for untrusted user requirements were identified.
  • Capability inventory: Subprocess execution for build tools (npm) and network utilities (curl), file system writes for project scaffolding, and significant code generation capabilities.
  • Sanitization: No specific sanitization or filtering of user-provided requirements is performed before they are used to guide code generation and testing.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 05:30 PM
Security Audit — agent-trust-hub — fullstack-dev