skills/arcblock/idd/intent-normalize/Gen Agent Trust Hub

intent-normalize

Pass

Audited by Gen Agent Trust Hub on Oct 4, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill performs various file system operations including reading markdown and YAML files, creating directories (records/, _archive/, _data/), and modifying file content (injecting frontmatter). These operations are well-defined within the context of documentation normalization and targeting specific project paths (intent/, planning/).
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user data (existing documentation files) and classifies them based on keywords (e.g., 'idea', 'research'). It mitigates risk by using a safe default classification ('idea') and does not execute content from these files as commands, instead tagging them for human or further automated review via a needs field.
  • [SAFE]: The execution logic is focused on structural and mechanical improvements to documentation. The 'pickup' mechanism for other skills (like /intent-interview) is an internal workflow management pattern and does not involve external remote code execution or data exfiltration.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 4, 2026, 12:42 PM