ceo-personal-os

Pass

Audited by Gen Agent Trust Hub on Aug 17, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [NO_CODE]: The skill consists entirely of Markdown files and documentation templates. There are no Python, Node.js, or shell scripts included in the package.- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to process documents from an uploads/ directory to summarize patterns and update a memory.md file. While this is a data ingestion surface, the risk is mitigated by the lack of high-privilege tools. * Ingestion points: User-provided files in the uploads/ directory. * Boundary markers: Not specified in the instructions. * Capability inventory: Limited to file reading and writing within the skill directory; no network or shell capabilities are present. * Sanitization: No explicit sanitization or filtering logic is defined for the uploaded content.- [SAFE]: All external URL references are for attribution purposes and target well-known services (e.g., x.com). These links do not involve automated downloads or remote code execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 17, 2026, 06:39 PM
Security Audit — agent-trust-hub — ceo-personal-os