scaffold-feature
Pass
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses shell commands like
ls -lato perform directory discovery and inspect the project's file structure to identify architectural patterns. - [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it is instructed to read complete source code files from the project to learn architectural patterns and naming conventions. If these existing project files contain hidden instructions, they could potentially influence the agent's behavior during the scaffolding process.
- Ingestion points: The agent is directed to read all files within an existing feature directory in
SKILL.md(Step 1). - Boundary markers: The skill does not define clear delimiters or provide instructions for the agent to ignore potentially malicious content embedded within the source files it reads.
- Capability inventory: The agent has the ability to write new files to the filesystem across all layers of the feature (Step 4).
- Sanitization: The skill lacks content validation or sanitization mechanisms for the data read from the local files before it is processed by the agent.
Audit Metadata