implement

Pass

Audited by Gen Agent Trust Hub on Jul 23, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes potentially untrusted external data (specifications or tickets) to drive implementation and testing tasks, which creates a surface for indirect prompt injection.\n
  • Ingestion points: Ingests specifications and tickets from users or external systems in SKILL.md.\n
  • Boundary markers: Absent. There are no delimiters or specific instructions to the agent to treat input as data only or to ignore embedded instructions.\n
  • Capability inventory: Possesses the ability to execute typechecking tools, run individual test files, execute full test suites, and perform code reviews via external tools (SKILL.md).\n
  • Sanitization: Absent. The skill does not describe any sanitization, validation, or filtering of the content provided in the tickets or specs.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 23, 2026, 01:46 PM
Security Audit — agent-trust-hub — implement