End To End App Development

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill architecture processes user-provided application goals and requirements to drive automated tasks like project scaffolding and dependency installation. This creates a standard surface where malicious user-provided instructions could attempt to influence downstream agent actions.
  • Ingestion points: User-defined problem statements, personas, and requirements captured in Phase 1 (Ideation) and Phase 2 (PRD).
  • Boundary markers: The skill relies on its 8-phase sequential structure but does not define explicit delimiters to isolate user-provided data from system instructions.
  • Capability inventory: The skill executes shell commands for project scaffolding (npx create-vite) and package management (npm install) during Phases 5 and 6.
  • Sanitization: The skill includes a dedicated 'Security Audit' in Phase 8 to check for exposed API keys and common web vulnerabilities like XSS and SQL injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 01:26 PM
Security Audit — agent-trust-hub — End To End App Development