mcaf-devex
Pass
Audited by Gen Agent Trust Hub on May 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill focuses on improving developer productivity through better documentation, standardized setup commands, and reproducible local environments.
- [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it ingests untrusted data from the repository's current setup, build, and test commands.
- Ingestion points: Reads the current local setup and command instructions (SKILL.md).
- Boundary markers: Not present; the instructions do not explicitly warn the agent to ignore instructions embedded in the project files.
- Capability inventory: The skill can modify project documentation, configuration files (e.g., devcontainers, task runners), and scripts.
- Sanitization: None; the agent processes repository data directly to formulate its recommendations.
- Note: This is a common surface for developer tools and is considered low risk given the lack of network exfiltration or privilege escalation capabilities.
Audit Metadata