skills/toy-crane/skills/implement/Gen Agent Trust Hub

implement

Pass

Audited by Gen Agent Trust Hub on Aug 7, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute verification and tests as part of the implementation process. This is the primary intended function of the skill and relies on the repository's native testing and review harness.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from specification folders which may be user-provided or generated.
  • Ingestion points: Markdown files within the specification folder (SKILL.md identifies docs/specs/SLUG/spec.md and tasks/).
  • Boundary markers: No explicit delimiters or 'ignore embedded instructions' warnings are used when processing the specification content.
  • Capability inventory: The agent has the capability to write files, commit changes to Git, and run shell-based verification/tests.
  • Sanitization: The skill mitigates risks through a 'native review process' and explicit instructions to confirm ownership of ambiguous changes before proceeding, ensuring human or automated oversight.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 7, 2026, 04:00 AM
Security Audit — agent-trust-hub — implement