ln-35-surgical-change-implementer

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external inputs such as user requests, linked tasks, and repository plans, which could theoretically contain instructions intended to influence the agent's behavior.
  • Ingestion points: The skill reads data from "User request, linked task or plan," and "repository instructions" as defined in the Tool Routing section.
  • Boundary markers: The checklist mandates converting requirements into "traceable acceptance rows" (Checklist 1), which creates a structured internal representation of the task, though it does not explicitly use delimiter-based prompt isolation.
  • Capability inventory: The skill has authorized access to file editors, package managers, and repository-native command execution (build, test, and lint tools).
  • Sanitization: The instructions contain robust defensive rules, requiring the agent to "verify current official guidance, maintenance, security, license" for dependencies and to "Never sacrifice... security" for code minimalism.
  • [COMMAND_EXECUTION]: The skill uses repository-native tooling and package managers to implement and verify changes.
  • Evidence: The Tool Routing table and Checklist sections authorize the use of "package manager," "generation commands," and "Repository-defined build, lint, type, test, smoke, and runtime checks."
  • Context: These capabilities are essential for the skill's primary function of code implementation and are restricted to standard, repository-defined workflows.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 09:32 AM
Security Audit — agent-trust-hub — ln-35-surgical-change-implementer