skills/alemtuzlak/skills/touch-map/Gen Agent Trust Hub

touch-map

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes repository source files to identify dependencies and symbols as described in Procedure 3 of SKILL.md. Data ingestion occurs when reading local code files to build the dependency map. While explicit boundary markers and sanitization for this content are not specified in the skill body, the capability inventory is restricted to local file read/write operations (SKILL.md) with no network access or arbitrary code execution capabilities.
  • [COMMAND_EXECUTION]: The skill performs standard file system read and write operations on the .agent/domain-map.json file to maintain its state as outlined in Procedure 2 and 5 of SKILL.md. These operations are confined to the local repository context and are essential for the skill's primary functionality.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 07:40 PM
Security Audit — agent-trust-hub — touch-map