sparc-methodology

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill utilizes the claude-flow package, which is hosted on NPM and GitHub. These references are to official vendor resources on well-known services.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external data, creating a potential surface for indirect prompt injection.
  • Ingestion points: The researcher mode performs web searches and fetches external content, while the reviewer and analyzer modes process codebases and dependency information from the project environment.
  • Boundary markers: The skill does not explicitly define delimiters or specific 'ignore instructions' warnings for external content processed by its modes.
  • Capability inventory: The skill has significant capabilities including code implementation (coder), test execution (tdd), network access (researcher), and version control interaction (github_pr_manage).
  • Sanitization: There are no explicit sanitization or filtering instructions for content retrieved from external sources before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 06:12 AM
Security Audit — agent-trust-hub — sparc-methodology