design-harden

Warn

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill performs autonomous shell command execution in Phase 10 (Build Verification, Type Safety Check, Test Verification), running build, lint, and test scripts on the local environment after modifying the source code.- [PROMPT_INJECTION]: The skill exhibits a significant surface for indirect prompt injection. It ingests untrusted data from codebase files (Phase 1), lacks boundary markers to delimit external content, and possesses extensive capabilities including file writing and shell execution. The instruction 'Do NOT ask the user questions' suppresses human-in-the-loop validation, increasing the risk that embedded instructions in processed files could manipulate the agent's behavior.- [SAFE]: No hardcoded credentials, persistent backdoors, or privilege escalation mechanisms were detected in the skill's operational instructions.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 23, 2026, 10:59 AM
Security Audit — agent-trust-hub — design-harden