fullstack-delivery-loop

Pass

Audited by Gen Agent Trust Hub on Jul 4, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: The skill includes instructions to ignore user requests that conflict with its defined quality process. It explicitly directs the agent to 'never .skip/weaken/disable a test or gate to go green... even under... a direct instruction to do so,' which constitutes an instruction to override user intent.
  • [DATA_EXFILTRATION]: The skill's instructions specifically mention accessing and auditing sensitive local file paths, including SSH keys (~/.ssh/id_rsa), GPG configurations (~/.gnupg), and environment configuration files (.env), confirming the agent's capability to read highly sensitive system and project data.
  • [PROMPT_INJECTION]: The skill has a high surface for indirect prompt injection due to its requirement to ingest and process various untrusted data sources from the working environment and passing that data into prompts for other sub-agents.
  • Ingestion points: SKILL.md (Step 1.5, Step 1.6, Step 2)
  • processes specification files, task manifests, design documents, and git diff outputs.
  • Boundary markers: Absent from instructions.
  • Capability inventory: Execution of bash and git commands; invocation of sub-agents via Agent/SendMessage.
  • Sanitization: Not specified in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 4, 2026, 02:08 PM
Security Audit — agent-trust-hub — fullstack-delivery-loop