skills/boshu2/agentops/dcg/Gen Agent Trust Hub

dcg

Warn

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill relies on the dcg (destructive_command_guard) binary. The validation script (scripts/validate-dcg.sh) directs users to download and install this tool from an unverified GitHub repository (github.com/Dicklesworthstone/destructive_command_guard).
  • [COMMAND_EXECUTION]: The skill frequently executes the dcg CLI tool with various subcommands (doctor, explain, test, scan, packs) to inspect the environment and evaluate command safety. It also instructions the agent to execute alternative commands like git stash or git push --force-with-lease when standard destructive commands are blocked.
  • [PRIVILEGE_ESCALATION]: The skill references commands that perform system-level modifications. The dcg doctor output (in references/COMMANDS.md) indicates the binary resides in /usr/local/bin/, and dcg install (referenced in references/TROUBLESHOOTING.md) modifies the agent's configuration file at ~/.claude/settings.json to register execution hooks. The dcg update command also facilitates binary replacement.
  • [PERSISTENCE]: The skill provides functionality to install persistent scripts, specifically git pre-commit hooks (dcg scan install-pre-commit in references/COMMANDS.md), which automatically execute the scanner before each commit to the repository.
  • [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection as it processes untrusted command strings and repository content. While it emphasizes safety and human approval, the reliance on an external tool for parsing complex scripts presents a potential vector.
  • Ingestion points: Repository files scanned by dcg scan (references/COMMANDS.md), command strings passed to dcg explain (SKILL.md), and content of heredocs/inline scripts processed by the AST parser (references/CONFIG.md).
  • Boundary markers: The skill instructs the agent to use dcg explain to verify the reason for a block and present this trace to the user, acting as a functional boundary before any bypass is considered (SKILL.md).
  • Capability inventory: Subprocess calls for dcg, git, kubectl, rm, and other CLI tools across all instruction files, plus filesystem writes for configuration files (.dcg.toml).
  • Sanitization: The dcg tool performs normalization and context sanitization during its evaluation pipeline (SKILL.md), although the robustness against adversarial content is dependent on the external binary's implementation.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 14, 2026, 07:35 AM
Security Audit — agent-trust-hub — dcg