agency-senior-developer

Pass

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to the processing of external task data.
  • Ingestion points: The skill reads task lists provided by a Project Manager (PM) agent in the Task Analysis & Planning phase (SKILL.md).
  • Boundary markers: There are no defined delimiters or instructions for the agent to ignore or isolate instructions that may be embedded within the ingested task list.
  • Capability inventory: The skill possesses extensive code implementation capabilities, including Laravel/Livewire logic, FluxUI components, and Three.js scripts, which could be exploited if malicious tasks are provided.
  • Sanitization: The implementation methodology lacks steps for validating or sanitizing the input from the PM agent before the implementation process begins.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 11, 2026, 02:58 PM
Security Audit — agent-trust-hub — agency-senior-developer