estate-hygiene
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses shell commands including
git,grep,mv, andwcto gather evidence and manage repository files. It specifically implements a 'retire pattern' that moves directories to a~/trash/location. - [INDIRECT_PROMPT_INJECTION]:
- Ingestion points: Data is ingested from the file system, including repository names, git logs, and file contents via
grep -rl. It also reads configuration data from~/vault/missions.md. - Boundary markers: There are no boundary markers or instructions to isolate potentially malicious data found within the repositories being audited.
- Capability inventory: The skill possesses shell execution capabilities (
git,mv,grep) and file system write access for moving directories. - Sanitization: The skill lacks explicit sanitization or validation mechanisms for the data retrieved from repositories before it is processed by the agent.
Audit Metadata