skills/juanca202/sdd-devkit/arch-init/Gen Agent Trust Hub

arch-init

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill performs shell operations to initialize and configure the development environment. Evidence includes git init in SKILL.md (Paso 1.1), installation and scaffolding commands in SKILL.md (Paso 2.3), and the execution of test suites in references/quality-gate.md (Paso 6).
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user descriptions and delegates research to other agents, creating a surface for indirect prompt injection.
  • Ingestion points: SKILL.md Paso 2.1 (Capturing user needs via free-text input).
  • Boundary markers: Absent for the flow of user input into the sub-agent calls.
  • Capability inventory: Execution of shell commands for project scaffolding and test suites, and repository modification via git.
  • Sanitization: Absent; the skill executes researched commands without explicit safety validation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 08:06 PM
Security Audit — agent-trust-hub — arch-init