email

Pass

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface because it processes untrusted data from the local environment (such as project filenames and content) and user-supplied arguments to drive its execution logic.
  • Ingestion points: $ARGUMENTS variable and project manifest files (e.g., package.json, requirements.txt).
  • Boundary markers: Absent.
  • Capability inventory: Execution of package managers (npm, pip) and file system write operations for creating service layers and templates.
  • Sanitization: None detected; the skill relies on the agent's internal logic to interpret these inputs.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 23, 2026, 10:58 AM
Security Audit — agent-trust-hub — email