greenfield
Pass
Audited by Gen Agent Trust Hub on Mar 10, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill operates as a structured documentation and planning workflow. It prioritizes business logic and domain modeling over implementation, adhering to a 'planning only' constraint that prevents the execution of arbitrary code.- [PROMPT_INJECTION]: The skill uses strong directives ('MANDATORY IMPORTANT MUST') to enforce its waterfall methodology. These are behavioral constraints for the planning process and do not attempt to bypass safety filters. It also possesses an indirect injection surface as it ingests data via 'WebFetch' in Step 3 (Deep Research). However, the capability inventory is limited to research and planning tasks, and the process includes a mandatory boundary marker ('AskUserQuestion' validation at every stage), ensuring the user remains in control.- [DATA_EXFILTRATION]: The skill leverages web research tools to gather project-related information. Artifacts are stored locally in the 'plans/' directory. No evidence was found of sensitive file access, hardcoded credentials, or unauthorized network transmissions to non-whitelisted domains.
Audit Metadata