diagnose-project-rebuild

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Indirect Prompt Injection Surface. The skill is designed to ingest and analyze potentially untrusted data from inherited or messy projects, including code, documentation, and external AI analyses.
  • Ingestion points: Processes 'old files, surviving versions, code, screenshots, and partial memories' as evidence (SKILL.md).
  • Boundary markers: Includes instructions to establish an 'evidence boundary' and explicitly labels external AI proposals as non-authoritative evidence to triage rather than orders to execute.
  • Capability inventory: The skill facilitates reading broad project history and performing file system operations (repair, rebuild, delete) if authorized by the user.
  • Sanitization: Recommends a 'zero-context probe' (fresh sessions) to verify that new foundations are not contaminated by prior context or dead facts.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 05:59 AM
Security Audit — agent-trust-hub — diagnose-project-rebuild