feature-dev
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze and implement changes based on potentially untrusted external data from a codebase and user input. * Ingestion points: The skill ingests data from codebase files during 'Phase 2: Codebase Exploration' and processes arbitrary user input during 'Phase 1: Discovery'. * Boundary markers: The skill instructions do not define clear delimiters or specify that agents should ignore instructions embedded within the repository files being explored. * Capability inventory: The skill utilizes powerful tools including 'Write', 'Edit', 'Bash', and 'Task' which are used to execute changes and commands based on the analyzed data. * Sanitization: The skill lacks explicit validation or sanitization routines for the content it reads from the environment or user input. * Mitigation: The workflow includes mandatory human-in-the-loop checkpoints in Phases 3, 4, 5, and 6, which effectively reduces the risk of autonomous or unintentional malicious actions by requiring explicit user confirmation before sensitive steps.
Audit Metadata