mcaf-devex

Pass

Audited by Gen Agent Trust Hub on May 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill focuses on improving developer productivity through better documentation, standardized setup commands, and reproducible local environments.
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it ingests untrusted data from the repository's current setup, build, and test commands.
  • Ingestion points: Reads the current local setup and command instructions (SKILL.md).
  • Boundary markers: Not present; the instructions do not explicitly warn the agent to ignore instructions embedded in the project files.
  • Capability inventory: The skill can modify project documentation, configuration files (e.g., devcontainers, task runners), and scripts.
  • Sanitization: None; the agent processes repository data directly to formulate its recommendations.
  • Note: This is a common surface for developer tools and is considered low risk given the lack of network exfiltration or privilege escalation capabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
May 20, 2026, 07:12 PM
Security Audit — agent-trust-hub — mcaf-devex