ecosystem-autopsy
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes a bundled shell script
scripts/discover_unregistered.shand makes extensive use of theorganvmCLI tool to audit and manage the repository ecosystem. It also performs file system operations to write signal files toautopsy/signals/. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the local filesystem during the discovery phase, specifically directory and repository names. These names are subsequently used to generate migration signals in JSON format without explicit sanitization or boundary markers.
- Ingestion points:
scripts/discover_unregistered.shreads directory names from the filesystem during its search for.gitfolders. - Boundary markers: Absent. The skill does not implement delimiters or instructions to ignore embedded content in repository names.
- Capability inventory: The skill uses
findandgrepcommands via shell and writes JSON signal files to disk which are intended to be consumed by other skills. - Sanitization: Absent. The repository names are interpolated directly into JSON signal templates in Phase 4 of the workflow.
Audit Metadata