octocode-brainstorming

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill defines shell hooks in hooks/hooks.json that trigger the execution of the management script scripts/brainstorm-run.mjs using sh -c and Node.js during specific lifecycle events.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from multiple web search engines and external documents, creating a surface for injection.
  • Ingestion points: Web search results and external resources referenced in references/web-search-workers.md and references/tools.md.
  • Boundary markers: The skill instructs the agent to treat findings as leads and perform independent validation, but lacks technical delimiters for the ingested data.
  • Capability inventory: The skill has the capability to write local files for session management and execute shell commands through the hook system.
  • Sanitization: Instructions mandate a "stress-test" and perspective review to validate claims, which serves as a logical guardrail against untrusted input.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 06:17 AM
Security Audit — agent-trust-hub — octocode-brainstorming