feature-dev

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze and implement changes based on potentially untrusted external data from a codebase and user input. * Ingestion points: The skill ingests data from codebase files during 'Phase 2: Codebase Exploration' and processes arbitrary user input during 'Phase 1: Discovery'. * Boundary markers: The skill instructions do not define clear delimiters or specify that agents should ignore instructions embedded within the repository files being explored. * Capability inventory: The skill utilizes powerful tools including 'Write', 'Edit', 'Bash', and 'Task' which are used to execute changes and commands based on the analyzed data. * Sanitization: The skill lacks explicit validation or sanitization routines for the content it reads from the environment or user input. * Mitigation: The workflow includes mandatory human-in-the-loop checkpoints in Phases 3, 4, 5, and 6, which effectively reduces the risk of autonomous or unintentional malicious actions by requiring explicit user confirmation before sensitive steps.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 12:01 AM
Security Audit — agent-trust-hub — feature-dev