w-security

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes repository security documentation and code changes to identify defects. This creates an attack surface where malicious instructions embedded in the repository content could influence the agent's behavior.
  • Ingestion points: Repository security documentation and changed paths (SKILL.md).
  • Boundary markers: None specified to isolate documentation content from instruction context.
  • Capability inventory: The skill is authorized to execute security scripts and CI jobs defined within the repository (SKILL.md).
  • Sanitization: No sanitization or validation of the ingested documentation is described.
  • [COMMAND_EXECUTION]: The instructions allow the agent to run existing security scripts or CI jobs found in package.json or other documentation. While standard for security auditing, this enables the execution of arbitrary commands defined within the repository's configuration.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 12:07 AM
Security Audit — agent-trust-hub — w-security