feature-forge

Pass

Audited by Gen Agent Trust Hub on Aug 23, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [NO_CODE]: The skill consists entirely of Markdown instructions and reference templates. It does not contain any scripts (Python, Node.js), binaries, or shell commands.\n- [DATA_EXPOSURE]: There are no patterns involving the reading of sensitive files like .env or ~/.ssh. The skill's primary function is creating new documentation in a local specs/ directory.\n- [EXTERNAL_DOWNLOADS]: The skill does not attempt to fetch data from external URLs or package registries. All references are to local markdown files within the skill package.\n- [PROMPT_INJECTION]: The instructions focus on structured elicitation using the AskUserQuestions tool. There are no attempts to bypass safety filters or override agent constraints. The 'PM Hat' and 'Dev Hat' roles are internal framing for gathering requirements, not jailbreak attempts.\n- [INDIRECT_PROMPT_INJECTION]: While the skill processes user input to generate specifications, it does not execute this data or pass it to high-privilege tools. The risk of command injection or malicious instruction execution is negligible as the output is static Markdown text.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 23, 2026, 07:56 AM
Security Audit — agent-trust-hub — feature-forge