workflow

Pass

Audited by Gen Agent Trust Hub on Jun 23, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The workflow is designed as a modular system for software development. It uses standard development tools and practices without any detected malicious patterns or obfuscation.
  • [COMMAND_EXECUTION]: The project-initialization and feature-implementation skills are designed to execute shell commands (e.g., git init, pnpm install, npm create) for setting up project structures and running tests. This behavior is consistent with the primary purpose of a developer-focused agent and follows the technical stack specified in the project documentation.
  • [EXTERNAL_DOWNLOADS]: The skill references the installation of well-known and trusted packages from the NPM registry, such as @supabase/supabase-js, eslint, and prettier. These are industry-standard tools and do not represent a security risk.
  • [PROMPT_INJECTION]: The skill uses GUARDRAILS.md to define strict functional boundaries for the agent (e.g., forbidding code generation during the requirements phase). This is a safety feature intended to prevent scope creep and ensure logical progression, rather than a malicious attempt to bypass model safety filters.
  • [SAFE]: The PROJECT-CONTEXT.md protocol ensures the agent reads local documentation in the specs/ folder to maintain state across different sessions, which is a best practice for complex AI development tasks.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 23, 2026, 08:14 AM
Security Audit — agent-trust-hub — workflow