parallel-agent-contracts
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill defines mandatory verification steps using
npx tsc --noEmitto check for TypeScript errors andgrepto search the codebase for existing type definitions. These are standard development operations intended to ensure code integrity and prevent duplication. - [INDIRECT_PROMPT_INJECTION]: The skill provides a template for spawning implementation agents that includes a placeholder for a task description. This creates a data ingestion surface where external instructions are interpolated into agent prompts. However, the provided content is focused on code hygiene and does not include malicious override patterns.
- Ingestion points: Prompt Template in
SKILL.md. - Boundary markers: None explicitly defined for the interpolation placeholder.
- Capability inventory: Shell command execution (
tsc,grep) inSKILL.md. - Sanitization: None detected.
Audit Metadata