octocode-brainstorming
Pass
Audited by Gen Agent Trust Hub on Aug 25, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill defines shell hooks in
hooks/hooks.jsonthat trigger the execution of the management scriptscripts/brainstorm-run.mjsusingsh -cand Node.js during specific lifecycle events. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from multiple web search engines and external documents, creating a surface for injection.
- Ingestion points: Web search results and external resources referenced in
references/web-search-workers.mdandreferences/tools.md. - Boundary markers: The skill instructs the agent to treat findings as leads and perform independent validation, but lacks technical delimiters for the ingested data.
- Capability inventory: The skill has the capability to write local files for session management and execute shell commands through the hook system.
- Sanitization: Instructions mandate a "stress-test" and perspective review to validate claims, which serves as a logical guardrail against untrusted input.
Audit Metadata