lcs-task-executor

Pass

Audited by Gen Agent Trust Hub on Aug 9, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No high-severity security issues were detected. The skill follows safety best practices such as defaulting to human-in-the-loop (HITL) mode for sensitive tasks and requiring strict exit code verification (exit code 0) for all validation commands.\n- [PROMPT_INJECTION]: The skill processes external project files (PRD, SRS, tasks) to guide its implementation logic, which represents a potential surface for indirect prompt injection. This is a low-risk concern inherent to the skill's primary purpose of executing development tasks.\n
  • Ingestion points: Reads from .lcs/state.md, task-###.md, prd.md, srs.md, tests.md, and task-coverage.md.\n
  • Boundary markers: The skill does not explicitly use delimiters to isolate file content from its instruction context.\n
  • Capability inventory: The agent can modify project files and execute local shell commands for testing and linting.\n
  • Sanitization: No explicit sanitization or filtering of external file content is described.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 9, 2026, 03:52 AM
Security Audit — agent-trust-hub — lcs-task-executor