skills/boshu2/agentops/pattern-mining/Gen Agent Trust Hub

pattern-mining

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill defines a methodical 'Pattern Mining' workflow that uses repository-anchored exemplars and a separate holdout to validate abstractions. It uses standard local tools like ripgrep and a bash script that leverages jq for schema validation. No high-risk behaviors such as network exfiltration, credential harvesting, or remote code execution were identified.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted code implementations from the repository to extract recurring patterns. This creates a surface for indirect prompt injection, but the risk is mitigated by the structured workflow requirements. (1) Ingestion points: Repository code implementations (exemplars) and search results. (2) Boundary markers: No explicit prompt boundaries are defined for exemplar ingestion. (3) Capability inventory: Writing evidence artifacts to local scratch directories and executing a local validation script. (4) Sanitization: Employs a specific bash and jq script to validate the logical consistency and schema of output artifacts before promotion.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 10:34 AM
Security Audit — agent-trust-hub — pattern-mining