investigate-before-recommend

Pass

Audited by Gen Agent Trust Hub on Jun 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to use standard CLI tools such as gh repo clone and manus-mcp-cli to interact with and verify the user's infrastructure. These actions are appropriate for the skill's stated goal of grounded architectural analysis.\n- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it is designed to ingest and process data from external, potentially attacker-controlled sources.\n
  • Ingestion points: The agent is directed to read data from external sources including Supabase database tables, GitHub repository contents, and web-based admin dashboards (SKILL.md, references/investigation_checklist.md).\n
  • Boundary markers: There are no explicit instructions or delimiters defined to separate user-provided data from system instructions, meaning instructions embedded in a README or database record could influence the agent.\n
  • Capability inventory: The agent has the ability to execute shell commands and access the local file system while processing this external data.\n
  • Sanitization: The protocol does not include steps for sanitizing, filtering, or validating the content retrieved from external environments before interpretation.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 27, 2026, 02:53 PM
Security Audit — agent-trust-hub — investigate-before-recommend