Pass
Audited by Gen Agent Trust Hub on Mar 23, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface because it processes untrusted data from the local environment (such as project filenames and content) and user-supplied arguments to drive its execution logic.
- Ingestion points:
$ARGUMENTSvariable and project manifest files (e.g., package.json, requirements.txt). - Boundary markers: Absent.
- Capability inventory: Execution of package managers (npm, pip) and file system write operations for creating service layers and templates.
- Sanitization: None detected; the skill relies on the agent's internal logic to interpret these inputs.
Audit Metadata