recipe-front-build
Pass
Audited by Gen Agent Trust Hub on Jul 22, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill ingests data from local markdown files in
docs/plans/tasks/anddocs/plans/to drive sub-agent behavior, creating an indirect prompt injection surface. This risk is mitigated by the orchestrator's mandatory 4-step task cycle and final security-reviewer pass. Ingestion points:docs/plans/tasks/*.mdanddocs/plans/*.mdinSKILL.md. Boundary markers: Absent. Capability inventory: File system modification (via sub-agents), git commit, and sub-agent orchestration. Sanitization: Absent. - [COMMAND_EXECUTION]: The orchestrator performs automated
git commitand file cleanup operations after tasks pass quality gates. These actions are scoped to specific project directories and follow explicit user approval to enter autonomous mode.
Audit Metadata