feature-dev

Pass

Audited by Gen Agent Trust Hub on May 18, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its core functionality of reading and analyzing arbitrary codebase files. Maliciously crafted instructions within code comments or documentation in the analyzed repository could potentially influence the behavior of the sub-agents.
  • Ingestion points: Reads files from the codebase during Exploration (Phase 2) and Implementation (Phase 5).
  • Boundary markers: No explicit instructions to ignore embedded prompts are present in the workflow description.
  • Capability inventory: The skill has access to Bash, Write, Edit, and Read tools which are used for implementation and exploration.
  • Sanitization: No content sanitization or validation of the ingested code is specified before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
May 18, 2026, 10:29 AM
Security Audit — agent-trust-hub — feature-dev