operationalize
Pass
Audited by Gen Agent Trust Hub on Aug 15, 2026
Risk Level: SAFE
Full Analysis
- [DATA_EXPOSURE]: The skill is designed to write advisory operationalization proposals to a specific local directory:
.agents/scratch/operationalize/. This is a controlled workspace environment used for temporary session artifacts. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data including session logs, diffs, and artifacts to identify patterns and expertise.
- Ingestion points: Reads evidence from repository paths,
.agents/aodigests, and session artifacts (SKILL.md). - Boundary markers: None explicitly defined in instructions for incoming evidence data.
- Capability inventory: Limited to writing text-based advisory proposals to a local scratch directory.
- Sanitization: None specified; however, the skill explicitly states it does not validate its own output or control other invocations, and the resulting proposals are advisory only, significantly reducing the risk of a prompt injection chain.
Audit Metadata