backend-dotnet-implementation
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted ticket data as its primary input, which could serve as a vector for indirect prompt injection if the ticket content contains instructions intended to manipulate the agent's behavior during the implementation or validation steps.
- Ingestion points: External ticket data received in Step 1 ("Delimite").
- Boundary markers: The instructions do not specify delimiters or warnings to ignore instructions embedded within the ticket content.
- Capability inventory: Source code modification, shell command execution (build, test, analysis), and invocation of related skills (
backend-dotnet-padroes,backend-dotnet-code-review). - Sanitization: No explicit sanitization or filtering of the ticket content is described before processing.
- [COMMAND_EXECUTION]: The workflow requires the agent to execute local system commands for building the project, running tests, and performing static analysis to ensure implementation quality.
- [DYNAMIC_EXECUTION]: The verification phase (Step 3) involves running the solution's test suite and static analysis tools, which results in the execution of project-resident code at runtime.
Audit Metadata