feature-delivery

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill instructions require the agent to ingest and act upon potentially untrusted repository content, creating an indirect prompt injection surface. * Ingestion points: The agent is directed to read 'applicable instructions' and inspect 'architecture and tests' within the repository (SKILL.md, Step 1). * Boundary markers: Absent. There are no instructions to use delimiters or ignore embedded directives in the ingested content. * Capability inventory: The skill allows file system modifications during implementation and shell command execution during the verification and CI gate phases. * Sanitization: Absent. No validation or sanitization of repository content is required before the agent processes it.
  • [COMMAND_EXECUTION]: The skill facilitates the execution of repository-defined commands as part of the verification process. * Evidence: Instruction 8 directs the agent to 'Run focused verification... then the repository's broader production or CI gate'. This gives the agent the authority to execute scripts and commands defined within the workspace.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 06:52 PM
Security Audit — agent-trust-hub — feature-delivery