skills/boshu2/agentops/premortem/Gen Agent Trust Hub

premortem

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted plan data (referred to as the 'intent source' or 'bead') and instructs the agent to actively attempt to 'defeat' the plan. If a malicious plan contains embedded instructions or commands disguised as legitimate rollout steps, the agent might execute them while following the instruction to 'run the check' to see if the plan survives the defeat attempt.
  • Ingestion points: The skill resolves and inspects existing intent sources and rollout plans (SKILL.md, Workflow Step 1).
  • Boundary markers: There are no explicit delimiters or instructions to ignore embedded commands within the input plan data.
  • Capability inventory: The agent is explicitly instructed to 'run or cite the check' and 'write the input, command sequence' (SKILL.md, Adversarial defeat attempts).
  • Sanitization: No validation or sanitization of the input plan's content is described before the agent attempts to 'defeat' it.
  • [DYNAMIC_EXECUTION]: The 'Adversarial defeat attempts' section in SKILL.md directs the agent to 'write the input, command sequence... and run or cite the check'. This encourages the agent to generate and execute shell commands or scripts at runtime based on its analysis of the plan. While intended for testing the plan's robustness, this behavior can be exploited if the agent is not strictly constrained in the types of commands it can generate and execute.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 05:10 PM
Security Audit — agent-trust-hub — premortem