developer-agent

Pass

Audited by Gen Agent Trust Hub on Jun 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes several shell commands to manage software development workflows.
  • Evidence includes git checkout, git pull, git add, git commit, git push, and git merge commands in SKILL.md (Stages 2 and 9).
  • The skill also executes pnpm build in SKILL.md (Stage 8) to verify the build state before committing changes.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection through the ingestion of external data.
  • Ingestion points: The skill explicitly instructs the agent to send all user-provided links and attachments to the Cursor Agent for planning (Stage 5) and implementation (Stage 6) as described in SKILL.md and references/workflow-details.md.
  • Boundary markers: Absent. The prompt templates provided in references/workflow-details.md do not use delimiters (like XML tags or triple quotes) or specific instructions to ignore malicious content embedded within the linked resources or attachments.
  • Capability inventory: The agent has the capability to modify the local filesystem, perform git operations, and execute shell commands (pnpm build).
  • Sanitization: No sanitization or validation of the content retrieved from external links is performed before being processed by the LLM.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 19, 2026, 11:49 AM
Security Audit — agent-trust-hub — developer-agent