skills/nxxxsooo/loop/deep-build/Gen Agent Trust Hub

deep-build

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external, untrusted data including project instructions, current system state, and build contracts.
  • Ingestion points: Found in SKILL.md where the agent is instructed to read the target project's instructions and current state.
  • Boundary markers: The instructions lack specific delimiters or instructions to ignore potential commands embedded within the external documents.
  • Capability inventory: The agent has the authority to modify code, execute verification tasks, and perform UI interactions as outlined in SKILL.md and agents/openai.yaml.
  • Sanitization: There are no explicit requirements for sanitizing or validating the input from these external sources before the agent acts on them.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 12:17 PM
Security Audit — agent-trust-hub — deep-build