reconnaissance

Pass

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill uses authoritative language to define strict workflow constraints (e.g., "MANDATORY GATE", "NON-NEGOTIABLE", "NEVER offer"). These instructions are used to enforce a specific project management framework and prevent the agent from skipping required review phases.
  • [COMMAND_EXECUTION]: The skill performs file system operations including reading codebase configuration files (e.g., package.json, requirements.txt, go.mod), internal documentation, and writing reconnaissance reports and checkpoints to the project directory.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from the target codebase which represents an untrusted input surface.
  • Ingestion points: Reads files, test configurations, and documentation during the codebase survey step in SKILL.md.
  • Boundary markers: None identified; reports from subagents are synthesized directly into the dossier.
  • Capability inventory: File system writes (dossier and checkpoints) and invocation of subsequent workflow tools (e.g., gangsta:the-sit-down).
  • Sanitization: No explicit sanitization or filtering of ingested codebase content is specified.
  • [EXTERNAL_DOWNLOADS]: No network operations or external downloads were identified.
Audit Metadata
Risk Level
SAFE
Analyzed
May 15, 2026, 02:10 PM
Security Audit — agent-trust-hub — reconnaissance