workspace-autopsy-governance

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
  • [COMMAND_EXECUTION]: The skill relies on shell command execution for its core functionality. It executes a local Python script (workspace_autopsy.py) to map the directory structure and instructs the agent to use the mv command for migrating files across the workspace. While these actions are intended for restructuring, the ability to perform bulk file operations across a repository carries an inherent risk of unintended data displacement or loss if the agent misinterprets the project structure or the user's intent during the migration phase.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data in the form of directory and file names when generating the autopsy report. If a user's workspace contains files with names that mimic system instructions or agent directives, these could potentially bias the agent's proposed restructuring plan or the generation of governance rules.
  • Ingestion points: The output of scripts/workspace_autopsy.py in Phase 1, which generates a comprehensive list of all file and folder names in the target directory.
  • Boundary markers: The skill lacks explicit instructions or delimiters to ensure the agent treats the discovered filenames strictly as data rather than potential directives.
  • Capability inventory: The agent possesses the capability to execute shell commands (mv), create new directories, and write markdown files to the root directory.
  • Sanitization: No validation or filtering of the autopsy script's output is performed before it is processed by the agent.
  • [METADATA_POISONING]: The SKILL.md instructions contain a hardcoded absolute path (/Users/4jp/.agents/skills/...) for the autopsy script. This indicates the skill is configured for a specific local environment and is not portable. This specific path reference is deceptive for general users as it points to a directory structure belonging to a specific user profile that will not exist on other machines.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 06:53 PM
Security Audit — agent-trust-hub — workspace-autopsy-governance