developer-agent
Pass
Audited by Gen Agent Trust Hub on Jun 19, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes several shell commands to manage software development workflows.
- Evidence includes
git checkout,git pull,git add,git commit,git push, andgit mergecommands inSKILL.md(Stages 2 and 9). - The skill also executes
pnpm buildinSKILL.md(Stage 8) to verify the build state before committing changes. - [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection through the ingestion of external data.
- Ingestion points: The skill explicitly instructs the agent to send all user-provided links and attachments to the Cursor Agent for planning (Stage 5) and implementation (Stage 6) as described in
SKILL.mdandreferences/workflow-details.md. - Boundary markers: Absent. The prompt templates provided in
references/workflow-details.mddo not use delimiters (like XML tags or triple quotes) or specific instructions to ignore malicious content embedded within the linked resources or attachments. - Capability inventory: The agent has the capability to modify the local filesystem, perform git operations, and execute shell commands (
pnpm build). - Sanitization: No sanitization or validation of the content retrieved from external links is performed before being processed by the LLM.
Audit Metadata