skills/ruvnet/ruflo/sparc-implement/Gen Agent Trust Hub

sparc-implement

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill retrieves and processes feature specifications and requirements from a memory store (sparc-phases namespace) in Step 1. This untrusted data is then used to generate algorithms, architecture designs, and ultimately production code and shell commands.
  • Ingestion points: The mcp__plugin_ruflo-core_ruflo__memory_search tool is used to ingest external requirements in Step 1.
  • Boundary markers: The instructions do not specify any delimiters or safety markers to differentiate between instructions and data when processing the retrieved specifications.
  • Capability inventory: The skill has significant capabilities, including Bash for command execution and Write/Edit for file system modification, which are triggered during the implementation phase in Step 8.
  • Sanitization: There is no explicit requirement for the agent to sanitize or validate the content of the retrieved specifications before they influence the implementation process.
  • [COMMAND_EXECUTION]: The skill explicitly includes Bash in its allowed-tools and utilizes it during Step 8 to perform implementation tasks and run tests, allowing for general shell command execution within the workspace.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 11:38 AM
Security Audit — agent-trust-hub — sparc-implement