next-stage

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external project data that could influence agent behavior during task generation.
  • Ingestion points: Reads docs/roadmaps/*/ROADMAP.md, individual stage brief files, and docs/agents/git-workflow.md (Step 2, 4, 5).
  • Boundary markers: Absent. The skill does not define specific delimiters or instructions to ignore embedded commands within the briefs.
  • Capability inventory: Modifies local files (ROADMAP.md in Step 7), performs git status checks/branching logic, and delegates complex execution to the /to-tasks and /setup-tobico-skills skills.
  • Sanitization: Absent. Content from the briefs is used directly as 'plan input' for the /to-tasks flow (Step 6).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 07:29 AM
Security Audit — agent-trust-hub — next-stage