specialist-engineering-rapid-prototyper
Pass
Audited by Gen Agent Trust Hub on Aug 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill defines a legitimate engineering persona and provides guidance on using industry-standard tools (Next.js, Prisma, Supabase, Clerk) for rapid software development.
- [INDIRECT_PROMPT_INJECTION]: The skill incorporates untrusted user data directly into a subagent system prompt through a template variable.
- Ingestion points: SKILL.md (via the '{the user's question}' placeholder).
- Boundary markers: None provided to isolate user input from the system instructions.
- Capability inventory: The skill spawns a subagent using the 'Agent' tool but does not define additional dangerous capabilities.
- Sanitization: No escaping or validation is performed on the user-provided string before interpolation.
Audit Metadata