run-blueprint

Pass

Audited by Gen Agent Trust Hub on Aug 1, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill performs expected task management operations, including reading and writing to a local blueprint file and invoking other internal agent skills. No signs of malicious activity or security bypasses were found.- [INDIRECT_PROMPT_INJECTION]: The skill processes content from an external blueprint file. Evidence Chain: 1. Ingestion point: The skill reads the file path provided in $ARGUMENTS (SKILL.md). 2. Boundary markers: Absent. 3. Capability inventory: The skill can read/edit files and execute other internal skills (build-task, ship-it). 4. Sanitization: Absent. This indicates an attack surface for indirect prompt injection, but it is inherent to the skill's function as a task runner.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 1, 2026, 08:54 PM
Security Audit — agent-trust-hub — run-blueprint