intent-normalize
Pass
Audited by Gen Agent Trust Hub on Oct 4, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill performs various file system operations including reading markdown and YAML files, creating directories (
records/,_archive/,_data/), and modifying file content (injecting frontmatter). These operations are well-defined within the context of documentation normalization and targeting specific project paths (intent/,planning/). - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user data (existing documentation files) and classifies them based on keywords (e.g., 'idea', 'research'). It mitigates risk by using a safe default classification ('idea') and does not execute content from these files as commands, instead tagging them for human or further automated review via a
needsfield. - [SAFE]: The execution logic is focused on structural and mechanical improvements to documentation. The 'pickup' mechanism for other skills (like
/intent-interview) is an internal workflow management pattern and does not involve external remote code execution or data exfiltration.
Audit Metadata