feature-architect

Pass

Audited by Gen Agent Trust Hub on Apr 23, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by ingesting external data from issue tracker tickets (via get_issue MCP) or testing reports. Ingestion points: SKILL.md Step 1 and references/issues-as-intent.md. Boundary markers: Absent; user input is recorded verbatim. Capability inventory: Extensive project-wide file-read and directory-scanning capabilities defined in research.md and scan.md. Sanitization: Absent; the process relies on explicit user review and permission gates to mitigate risks.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 23, 2026, 02:26 PM