plaster-from-patch

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external code patches and Chromium source files to generate its output.
  • Ingestion points: Reads patch content using cat patches/<...>.patch and source code using git -C .. show HEAD:<path>.
  • Boundary markers: The instructions lack explicit delimiters or warnings to differentiate between instructions and the data being processed from the patches.
  • Capability inventory: The skill has extensive file system access (Read, Write, Edit) and the ability to execute shell commands via Bash (including python3, git, and pnpm).
  • Sanitization: No sanitization or validation is applied to the content extracted from the patches before it is used to author new configuration files.
  • [EXTERNAL_DOWNLOADS]: The skill may attempt to install a dependency from the public Python Package Index (PyPI).
  • Evidence: Step 3 includes an instruction to run python3 -m pip install pyyaml if the library is missing. PyYAML is a well-known and standard library for YAML parsing.
  • [COMMAND_EXECUTION]: The skill executes local repository scripts and system commands to verify the generated configuration.
  • Evidence: The skill runs tools/cr/plaster.py apply to regenerate patches and uses various standard utilities such as git, pnpm, and diff for workflow management and verification.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 09:03 PM
Security Audit — agent-trust-hub — plaster-from-patch