sparc-implement
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill retrieves and processes feature specifications and requirements from a memory store (
sparc-phasesnamespace) in Step 1. This untrusted data is then used to generate algorithms, architecture designs, and ultimately production code and shell commands. - Ingestion points: The
mcp__plugin_ruflo-core_ruflo__memory_searchtool is used to ingest external requirements in Step 1. - Boundary markers: The instructions do not specify any delimiters or safety markers to differentiate between instructions and data when processing the retrieved specifications.
- Capability inventory: The skill has significant capabilities, including
Bashfor command execution andWrite/Editfor file system modification, which are triggered during the implementation phase in Step 8. - Sanitization: There is no explicit requirement for the agent to sanitize or validate the content of the retrieved specifications before they influence the implementation process.
- [COMMAND_EXECUTION]: The skill explicitly includes
Bashin itsallowed-toolsand utilizes it during Step 8 to perform implementation tasks and run tests, allowing for general shell command execution within the workspace.
Audit Metadata