backprop
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [SAFE]: The skill provides a structured methodology for debugging and updating project documentation (Spec-Driven Development). No malicious intent, obfuscation, or unauthorized access patterns were detected.
- [INDIRECT_PROMPT_INJECTION]: The skill processes potentially untrusted content from external sources. Ingestion points: Failure output and bug reports (SKILL.md). Boundary markers: None identified. Capability inventory: Code modification, test file generation, and execution of test suites (SKILL.md). Sanitization: None identified. The attack surface is intrinsic to the skill's primary purpose of debugging.
- [DYNAMIC_EXECUTION]: The skill generates and executes code locally. Execution method: The agent creates new test files (e.g., 'TestV7_RefundIdempotent') and runs them via the command line to verify fixes (SKILL.md). This is standard behavior for a development-focused agent.
Audit Metadata