executar-bugfix

Pass

Audited by Gen Agent Trust Hub on Apr 5, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes shell commands using the bun runtime to perform validation tasks.
  • Evidence: Step 3 and Step 6 in SKILL.md instruct the agent to run bun run typecheck and bun run test on the codebase after modifications have been applied.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection where instructions hidden in the documentation files could override the agent's behavior.
  • Ingestion points: Step 1 in SKILL.md reads untrusted content from ./tasks/prd-[feature-slug]/bugs.md, prd.md, and techspec.md.
  • Boundary markers: Absent. The skill lacks delimiters or specific instructions to treat external data as untrusted or to ignore instructions embedded within these files.
  • Capability inventory: The agent possesses file-writing capabilities (Steps 3, 4, 7, 8), command execution capabilities (bun), and network navigation capabilities via Playwright MCP (browser_navigate).
  • Sanitization: Absent. There is no evidence of validation, escaping, or filtering of the ingested content before it is used to plan and implement code changes.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 5, 2026, 03:23 AM
Security Audit — agent-trust-hub — executar-bugfix