andrew-mode

Pass

Audited by Gen Agent Trust Hub on Aug 29, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill directs the agent to process potentially untrusted external content, including pull request bodies and documentation, creating a vulnerability surface where embedded instructions could influence behavior.\n
  • Ingestion points: Pull request bodies, commit messages, published documentation, and README files.\n
  • Boundary markers: No specific delimiters or "ignore" instructions are defined for this data ingestion.\n
  • Capability inventory: The agent is authorized to execute commands/experiments, write to the file system, and propose skill or code edits.\n
  • Sanitization: No sanitization or validation routines for external prose are specified.\n- [COMMAND_EXECUTION]: The instructions promote an autonomous approach where the agent is encouraged to run commands or experiments to resolve questions rather than prompting the user, and to proceed without asking on reversible actions, which reduces human oversight.\n
  • Evidence: "If running something would answer the question, run it. Asking is the slow path." and "Proceed without asking on anything reversible." (SKILL.md).\n- [SAFE]: The skill explicitly mandates human intervention for high-risk operations, providing a safety layer against accidental or malicious modifications to sensitive data.\n
  • Evidence: "Stop and ask for these only: commits, pushes, merges, deploys, edits to secrets or env, deletion of data or branches, and anything that reaches a third party." (SKILL.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 29, 2026, 03:27 PM
Security Audit — agent-trust-hub — andrew-mode