skills/backnotprop/pstack/why/Gen Agent Trust Hub

why

Pass

Audited by Gen Agent Trust Hub on Jul 4, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes standard command-line tools such as git and gh to extract version control history, line-level attribution, and pull request metadata. These operations are restricted to the local repository and the project's official GitHub environment.
  • [DATA_EXFILTRATION]: The skill aggregates data from internal sources (Slack, Notion, Datadog, Linear, Sentry, Databricks) using the Model Context Protocol (MCP). The purpose of this aggregation is to synthesize a 'why' report for the user. No evidence was found of data being transmitted to unauthorized external domains or third-party servers.
  • [INDIRECT_PROMPT_INJECTION]: By ingesting data from external sources like PR comments, Slack threads, and issue descriptions, the skill has an exposure surface for indirect prompt injection. However, the skill incorporates an 'Epistemics Framework' and specific 'Operating Postures' that instruct the agent to prioritize verbatim citations and maintain high skepticism toward interpreted intent, which serves as a mitigation against such attacks.
  • [REMOTE_CODE_EXECUTION]: The skill orchestrates sub-agents (using composer-2.5-fast and claude-opus-4-7-thinking-xhigh) to perform parallel investigations. This is a legitimate architectural pattern for complex analysis tasks and does not involve the execution of untrusted remote scripts.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 4, 2026, 05:53 PM
Security Audit — agent-trust-hub — why