duck-critic

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface by processing untrusted artifacts (plans, code, tests) through a subagent-based review loop without explicit sanitization. 1. Ingestion points: User artifacts are ingested into packets for review (SKILL.md, references/critic-packets.md). 2. Boundary markers: Packet shapes provide basic delimiters like 'Goal:' and 'Evidence:' but do not sanitize content (references/critic-packets.md). 3. Capability inventory: The skill uses the 'runSubagent' capability to execute reviews and revise work based on feedback (references/harness-adapters.md). 4. Sanitization: No formal sanitization or content filtering is described before artifact interpolation.
  • [COMMAND_EXECUTION]: The skill instructions include a metadata discovery pattern to identify execution environment capabilities. It directs the agent to call 'runSubagent' with intentionally invalid model names, exploiting platform error messages to extract a list of all selectable models in the current session (references/harness-adapters.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 03:52 PM
Security Audit — agent-trust-hub — duck-critic