skills/benoror/dotfiles/skill-doctor/Gen Agent Trust Hub

skill-doctor

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses subprocess.run to execute git commands for repository discovery and path resolution. These commands are invoked with argument lists and without a shell, which is a safe implementation pattern for local developer tooling.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes potentially untrusted content from local agent conversation transcripts.
  • Ingestion points: Transcripts are gathered from local configuration directories (e.g., ~/.claude, ~/.codex) and SQLite databases by collect_sessions.py.
  • Boundary markers: Scored transcripts are rendered with clear markdown delimiters in the LLM's context during the aggregation and scoring phase.
  • Capability inventory: The skill is restricted to local file reads and writes within a temporary directory, alongside read-only git operations. It contains no network exfiltration or persistent execution capabilities.
  • Sanitization: A looks_injected function detects and filters potential system prompt overrides or tag-based injections within the transcript text, and the final HTML report implementation utilizes standard escaping to mitigate browser-side risks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 06:43 PM
Security Audit — agent-trust-hub — skill-doctor