agile-v-control-matrix
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill requires the agent to read and follow instructions from external YAML and Markdown files, which could be exploited if these files contain malicious instructions.
- Ingestion points: The skill reads .agile-v/CONTROL_MATRIX.yaml, .agile-v/CHECKPOINTS.md, and .agile-v/APPROVALS.md.
- Boundary markers: The instructions do not specify any delimiters or safety warnings for the agent when processing the content of these external files.
- Capability inventory: The agent makes decisions about tool use, permissions, and human gates based on the ingested data.
- Sanitization: No specific input validation or sanitization methods for the external configuration files are described.
- [COMMAND_EXECUTION]: The skill documentation mentions the use of the agilev CLI tool for runtime governance.
- Evidence: The skill instructs the user/agent to use agilev controls validate to ensure matrix compliance. This is a vendor-owned resource.
Audit Metadata