recipe-fullstack-build

Pass

Audited by Gen Agent Trust Hub on Jul 22, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill manages a task execution pipeline that processes local markdown files, which is an indirect prompt injection surface.\n- Ingestion points: Task files are read from the docs/plans/tasks/ directory and work plans are resolved via the $ARGUMENTS variable.\n- Boundary markers: The skill mandates that a [SYSTEM CONSTRAINT] suffix be appended to every sub-agent prompt to maintain operational boundaries.\n- Capability inventory: The orchestrator can spawn sub-agents, execute git commits, and delete files in the tasks directory.\n- Sanitization: Implements multi-agent verification including a security-reviewer agent and a 4-step execution cycle.\n- [COMMAND_EXECUTION]: The skill performs routine development tasks such as committing code and cleaning up temporary files.\n- Evidence: Uses git commit for approved code changes and deletes task files within the docs/plans/tasks/ directory upon completion.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 22, 2026, 10:14 PM
Security Audit — agent-trust-hub — recipe-fullstack-build