skills/boshu2/agentops/reality-check/Gen Agent Trust Hub

reality-check

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes the ao command-line utility for goal measurement (measure, validate, drift, history, export, meta, scenarios, render) and status checks (ao status).
  • [COMMAND_EXECUTION]: The skill runs local shell scripts scripts/validate-output.sh and scripts/validate.sh to perform integrity checks on generated reports and its own configuration.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data sources (source code, artifacts, GOALS.md) which could contain malicious instructions meant to influence the reality check report.
  • Ingestion points: Reads claims from source documents, repository artifacts, command outcomes, and goal files (GOALS.md or legacy YAML).
  • Boundary markers: The instructions provide clear constraints to report only facts and gaps, prohibiting the agent from issuing a 'verdict' or 'PASS' and from selecting new work based on findings.
  • Capability inventory: File system writes to .agents/scratch/ and .agents/ao/goals/baselines/, execution of the ao CLI tool, and execution of local shell scripts.
  • Sanitization: No explicit sanitization or filtering of evidence content is mentioned before it is included in the report findings.
  • [DATA_EXPOSURE]: Accesses internal platform metadata and artifact stores located in .agents/ao/intents/ and .agents/ao/verdicts/ to report recency and recency of evidence.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 05:10 PM
Security Audit — agent-trust-hub — reality-check