create-prototype

Pass

Audited by Gen Agent Trust Hub on Mar 25, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data which could contain malicious instructions to influence the agent's code generation behavior.
  • Ingestion points: The skill reads user_story variables and files located in .agents/flow/ (JSON/Markdown PRDs).
  • Boundary markers: Absent. There are no explicit delimiters or instructions to ignore commands embedded within the user story or PRD data.
  • Capability inventory: The agent has the ability to create and modify files within the project workspace.
  • Sanitization: Absent. The skill does not perform validation or filtering on the content of the ingested requirement documents.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 25, 2026, 04:49 AM