feature-architect
Pass
Audited by Gen Agent Trust Hub on Apr 23, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by ingesting external data from issue tracker tickets (via get_issue MCP) or testing reports. Ingestion points: SKILL.md Step 1 and references/issues-as-intent.md. Boundary markers: Absent; user input is recorded verbatim. Capability inventory: Extensive project-wide file-read and directory-scanning capabilities defined in research.md and scan.md. Sanitization: Absent; the process relies on explicit user review and permission gates to mitigate risks.
Audit Metadata