agy-headless-evidence
Pass
Audited by Gen Agent Trust Hub on Jun 28, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides instructions for running the
agyCLI tool headlessly using various flags, including--dangerously-skip-permissions. To mitigate the risk of this flag, the skill explicitly mandates that thedcg(destructive-command guard) must be active at the environment level to intercept and block potentially malicious shell commands. - [INDIRECT_PROMPT_INJECTION]: The workflow involves capturing agent event streams (
events.jsonl) which are intended to be processed by downstream validators. This establishes an ingestion surface for automated agent data, though the skill focuses on the evidence-gathering and storage mechanism rather than the execution of the captured data.
Audit Metadata