phased-implement

Pass

Audited by Gen Agent Trust Hub on Jun 20, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes an arbitrary validation command provided via the --validation command-line argument or defined within the validation field of the master plan YAML block. This is a core functionality for verifying implementation phases but represents a command execution vector if the source of the plan is untrusted.\n- [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it ingests untrusted data from the repository's source code and external master plan files. This data is used to generate implementation plans and is interpolated into the instructions provided to sub-agents.\n
  • Ingestion points: The skill reads local files using Glob and Read tools to generate plans and loads external master plan files provided via the --plan argument. It also reads result sentinels written by other agents in the captures/ directory.\n
  • Boundary markers: The skill uses Markdown headers and structured sections (e.g., ## Phase context, ## Acceptance criteria) in its prompt templates to delineate context for sub-agents.\n
  • Capability inventory: The skill executes shell commands via the Bash tool for git operations, workmux orchestration, and the user-specified validation commands.\n
  • Sanitization: No explicit sanitization or validation of the ingested repository content or plan data is mentioned before it is interpolated into prompts or executed as commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 20, 2026, 04:06 PM
Security Audit — agent-trust-hub — phased-implement