skills/boshu2/agentops/agent-native/Gen Agent Trust Hub

agent-native

Pass

Audited by Gen Agent Trust Hub on Oct 4, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes local CLI tools such as 'ao' and 'claude' for session management and model interaction. It also includes a Python-based test runner ('scripts/fake_model_runner.py') designed to simulate model responses during conformance testing, which operates deterministically using standard libraries.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines an architecture for processing external files through delegated roles such as 'bulk-reader' and 'code-writer'. Ingestion occurs through file read and write operations initiated by these roles. Boundary markers are established via explicit instructions to sub-agents to treat file content as evidence rather than instructions. Capabilities are strictly scoped to file operations with sanitization requirements, including symlink resolution and path normalization, to prevent unauthorized access or modification.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 4, 2026, 10:55 AM
Security Audit — agent-trust-hub — agent-native