kiro-validate-impl

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill identifies and executes local project commands for testing and validation (e.g., scripts in package.json or Makefile). While this involves running arbitrary project code, it is the intended primary function for providing integration feedback.
  • [PROMPT_INJECTION]: The skill processes project-specific documentation and specifications, creating an indirect prompt injection surface. Ingestion points: .kiro/specs/*.md, product.md, and tech.md. Boundary markers: None explicitly defined. Capability inventory: Executes project scripts and filesystem searches. Sanitization: None. This is considered a low risk given the professional development context.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 01:15 AM
Security Audit — agent-trust-hub — kiro-validate-impl