feature-dev-next
Pass
Audited by Gen Agent Trust Hub on May 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: Workflow Orchestration: The skill implements a legitimate development framework using sub-agents and local tools for codebase exploration and implementation. No unauthorized command execution or privilege escalation patterns are present.
- [SAFE]: Indirect Prompt Injection: The skill processes local repository data which constitutes an injection surface. 1. Ingestion points: Codebase files read in Stage 2/4 and plan documents in Stage 0. 2. Boundary markers: Not explicitly defined in agent prompts. 3. Capability inventory: Agent tool execution, file read/write, and developer tool invocations. 4. Sanitization: No explicit content sanitization. This surface is typical for developer tools and is mitigated by a security-specific review step.
- [SAFE]: Data Integrity: The skill accesses only the relevant project codebase and planning files. No hardcoded secrets or exfiltration patterns to non-whitelisted domains were found.
Audit Metadata