iterate-with-prototypes

Pass

Audited by Gen Agent Trust Hub on Aug 8, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [SAFE]: A comprehensive analysis of the skill's instructions and reference files shows no evidence of malicious patterns, obfuscation, or unauthorized credential access. The logic is entirely focused on enhancing legitimate software engineering processes.\n- [PROMPT_INJECTION]: The skill identifies and ingests external documentation such as PRDs, specifications, and plans to inform its prototyping and implementation phases, which creates an indirect prompt injection surface common to technical assistants.\n
  • Ingestion points: Project-specific PRD, specification, and plan files referenced during target identification.\n
  • Boundary markers: The instructions do not define specific delimiters to isolate user instructions from ingested documentation content.\n
  • Capability inventory: The skill generates code (Code-A), performs file-system modifications, and invokes sub-skills like /prototype for code execution.\n
  • Sanitization: The skill does not implement specific sanitization or filtering for ingested documentation.\n- [EXTERNAL_DOWNLOADS]: The skill references recommended external utilities like /prototype and /grill-with-docs that are required for the full iteration loop but are not bundled with the skill repository. The instructions explicitly state these require separate installation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 8, 2026, 02:22 AM
Security Audit — agent-trust-hub — iterate-with-prototypes