skills/toy-crane/skills/implement/Gen Agent Trust Hub

implement

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided content from specification folders (docs/specs/), including specifications, task lists, and visual prototypes, to drive its implementation logic. This creates a surface where instructions embedded in project data could influence agent behavior.
  • Ingestion points: The agent reads spec.md, task files, and reference artifacts within the selected spec folder (SKILL.md line 36).
  • Boundary markers: While the skill uses a 'reconciliation' phase to identify conflicts, it lacks explicit instructions to treat the external documentation as untrusted or to ignore embedded instructions.
  • Capability inventory: The agent can write source code, execute shell commands for development servers and verification, and transmit data externally for review.
  • Sanitization: No explicit sanitization or filtering of the ingested documentation is defined.
  • [DATA_EXFILTRATION]: The skill implements a workflow for sending implementation diffs and specifications to external services (such as OpenAI) for automated code review. While this transmits project code to third-party infrastructure, it is managed as a core feature with clear user authorization guidelines.
  • Evidence: The skill instructions emphasize identifying the service and the context being sent, carrying user authorization into the request, and forbidding the use of alternative tools to bypass security denials (SKILL.md lines 135-155).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 09:24 AM
Security Audit — agent-trust-hub — implement