backend

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a local project binary located at ./bin/hushh. This tool is used for retrieving protocol help information, launching local development terminal environments (e.g., backend and stack modes), and managing backend operations.
  • [COMMAND_EXECUTION]: The skill invokes pytest via python3 -m pytest to execute backend tests within the consent-protocol directory as part of its required verification workflow.
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it ingests various repository files while maintaining command execution capabilities.
  • Ingestion points: The skill reads consent-protocol/README.md, consent-protocol/docs/README.md, docs/reference/architecture/architecture.md, and docs/project_context_map.md.
  • Boundary markers: No explicit delimiters or instructions to ignore embedded commands are present in the documentation ingestion process.
  • Capability inventory: The skill has the capability to execute shell commands through the ./bin/hushh binary and the pytest testing framework.
  • Sanitization: There is no evidence of sanitization or validation of the content within the ingested markdown files before they are processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 02:58 AM
Security Audit — agent-trust-hub — backend