ecosystem-autopsy

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a bundled shell script scripts/discover_unregistered.sh and makes extensive use of the organvm CLI tool to audit and manage the repository ecosystem. It also performs file system operations to write signal files to autopsy/signals/.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the local filesystem during the discovery phase, specifically directory and repository names. These names are subsequently used to generate migration signals in JSON format without explicit sanitization or boundary markers.
  • Ingestion points: scripts/discover_unregistered.sh reads directory names from the filesystem during its search for .git folders.
  • Boundary markers: Absent. The skill does not implement delimiters or instructions to ignore embedded content in repository names.
  • Capability inventory: The skill uses find and grep commands via shell and writes JSON signal files to disk which are intended to be consumed by other skills.
  • Sanitization: Absent. The repository names are interpolated directly into JSON signal templates in Phase 4 of the workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 06:53 PM
Security Audit — agent-trust-hub — ecosystem-autopsy