skills/a-canary/arc-skills/wizard/Gen Agent Trust Hub

wizard

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill generates and directs the execution of bash scripts (based on template.sh) which perform shell-based operations, including file writes and repository management via the gh CLI tool.- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to analyze local project files to discover configuration requirements.
  • Ingestion points: Accesses .env files, README, docker-compose files, and .github/workflows/* within the local environment (SKILL.md).
  • Boundary markers: None specified for the analysis of local files.
  • Capability inventory: The resulting scripts can write to .env files, open URLs in a browser, and modify GitHub secrets and variables using the gh command-line utility.
  • Sanitization: No specific filtering is applied to the values read from the environment or input by the user before they are processed by the generated script.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 01:03 AM
Security Audit — agent-trust-hub — wizard