feature-builder

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides standard build and test commands for mobile development environments, including ./gradlew for Android/JVM and xcodebuild for iOS. These are standard industry tools for the stated purpose and do not include any suspicious flags, remote downloads, or privilege escalation attempts.
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates an end-to-end workflow starting from user-provided feature ideas. Although it processes external input, it uses a structured multi-phase approach with internal skill references, effectively delimiting the processing environment and reducing the risk of unintended instruction execution.
  • [NO_CODE]: The skill is primarily composed of markdown instructions, tables, and workflow descriptions. It does not include executable scripts, binary files, or complex runtime automation, which significantly minimizes its potential for malicious behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 08:11 PM
Security Audit — agent-trust-hub — feature-builder