skills/anentrypoint/gm/gm-continue/Gen Agent Trust Hub

gm-continue

Pass

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill uses extremely imperative and restrictive language to override agent decision-making and autonomy, mandating that the agent 'Never end that turn with prose alone' and follow a rigid state machine with 'no exceptions.'
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from local configuration files to determine instructions for subsequent tool calls, creating an attack surface for instructions embedded in these files to influence agent behavior.
  • Ingestion points: Reads configuration and task lists from .gm/prd.yml and .gm/mutables.yml.
  • Boundary markers: No specific delimiters or safety instructions are provided to the agent for parsing the contents of these files.
  • Capability inventory: The skill dispatches other tools via Skill(skill='gm') or Skill(skill='wfgy-method') and has access to Read, Write, and Bash tools.
  • Sanitization: The instructions do not define any validation or sanitization for the data read from external files.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 15, 2026, 07:51 AM
Security Audit — agent-trust-hub — gm-continue