senior-fullstack

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local Python scripts (project_scaffolder.py and code_quality_analyzer.py) to automate project setup and perform code audits. These tools possess the capability to read, create, and modify files within the local file system based on user-provided paths and arguments.- [PROMPT_INJECTION]: The code_quality_analyzer.py tool ingests and processes content from project files to identify security patterns and complexity metrics. This ingestion of untrusted data represents an indirect prompt injection surface where malicious instructions embedded in the analyzed code could potentially influence the behavior of the AI agent during the analysis process.
  • Ingestion points: scripts/code_quality_analyzer.py reads code and configuration files from the directory path provided as a tool argument.
  • Boundary markers: The tool does not implement specific delimiters or 'ignore' instructions to isolate the scanned code content from the agent's core instruction set.
  • Capability inventory: The skill can read local files, create directories and files (scripts/project_scaffolder.py), and execute Python-based logic.
  • Sanitization: No sanitization or safety filtering is applied to the ingested code content before it is evaluated or reported to the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 03:25 PM
Security Audit — agent-trust-hub — senior-fullstack