zero-to-prod-orchestrator

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONOBFUSCATION
Full Analysis
  • [OBFUSCATION]: The skill contains a non-printable ASCII control character (specifically the Bell character \x07) immediately preceding the string "utonomous-red-teamer" in Phase 6 of both the English and Bahasa Indonesia orchestration sections. While potentially a copy-paste error, non-printable characters are often used to evade simple keyword-based security filters.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a complex workflow that ingests untrusted data which directly influences the generation of code and infrastructure configuration.
  • Ingestion points: Phase 1 (Discovery) involves structured dialogue with users and the use of tools like web-scraper and deep-research-analyst to define product requirements.
  • Boundary markers: The instructions do not specify any delimiters or safety guardrails to prevent instructions embedded within user requirements or scraped web content from being executed as commands or logic in the generated codebase.
  • Capability inventory: The skill is designed to perform significant file-system operations (writing PRD.md, ERD.md, ROADMAP.md, PROGRESS.md, BLUEPRINT.md, and code scaffolding across multiple languages), configure CI/CD pipelines, and set up database schemas.
  • Sanitization: No explicit sanitization or validation logic is defined for the external data ingested during the discovery phase before it is used to orchestrate complex development tasks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 01:29 PM
Security Audit — agent-trust-hub — zero-to-prod-orchestrator