skills/dokhacgiakhoa/antigravity-ide/full-stack-orchestration-full-stack-feature/Gen Agent Trust Hub
full-stack-orchestration-full-stack-feature
Pass
Audited by Gen Agent Trust Hub on Apr 8, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill architecture is vulnerable to indirect prompt injection through the use of the
$ARGUMENTSvariable which passes untrusted data to sub-agents.\n - Ingestion points: User input via
$ARGUMENTSis interpolated into prompts across multiple files, includingsub-skills/1-database-architecture-design.md,sub-skills/4-backend-service-implementation.md, andsub-skills/12-performance-optimization.md.\n - Boundary markers: The prompts lack clear delimiters (such as XML tags or triple quotes) or specific instructions to the sub-agents to ignore potential instructions embedded within the user-provided feature descriptions.\n
- Capability inventory: The sub-agents invoked have significant capabilities, including generating backend and frontend code, creating database migration scripts, and configuring infrastructure and CI/CD pipelines through the
Tasktool.\n - Sanitization: There is no implementation of input validation or sanitization before user-provided data is processed by the orchestration logic.
Audit Metadata