ponytail-debt
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from codebase comments, which constitutes a surface for indirect instructions to influence the agent.
- Ingestion points: The skill uses
grepto extract text from every file in the repository that contains theponytail:prefix. - Boundary markers: There are no boundary markers or instructions to treat the harvested comment text as data rather than instructions.
- Capability inventory: The skill executes shell commands (
grep,git blame) and has the capability to write a ledger to the filesystem (e.g.,PONYTAIL-DEBT.md). - Sanitization: There is no evidence of sanitization or filtering applied to the harvested comment content before it is processed or written to output.
- [COMMAND_EXECUTION]: The skill invokes shell utilities to perform its core functionality.
- Evidence: The instructions explicitly direct the agent to run
grep -rnE '(#|//) ?ponytail:' .and potentiallygit blameon specific lines to gather data from the local environment.
Audit Metadata