specialist-engineering-rapid-prototyper

Pass

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill defines a legitimate engineering persona and provides guidance on using industry-standard tools (Next.js, Prisma, Supabase, Clerk) for rapid software development.
  • [INDIRECT_PROMPT_INJECTION]: The skill incorporates untrusted user data directly into a subagent system prompt through a template variable.
  • Ingestion points: SKILL.md (via the '{the user's question}' placeholder).
  • Boundary markers: None provided to isolate user input from the system instructions.
  • Capability inventory: The skill spawns a subagent using the 'Agent' tool but does not define additional dangerous capabilities.
  • Sanitization: No escaping or validation is performed on the user-provided string before interpolation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 15, 2026, 08:50 PM
Security Audit — agent-trust-hub — specialist-engineering-rapid-prototyper