breakthrough-performance-db-setup

Pass

Audited by Gen Agent Trust Hub on Aug 29, 2026

Risk Level: SAFECREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The files references/template-and-teaching.md and references/changing-the-base.md include a hardcoded Lark Base token (Yt2WbfTeQa0tjQsjMUwlfaEvgXb). This token refers to a vendor-owned template intended for duplication by the student.\n- [EXTERNAL_DOWNLOADS]: The skill instructs the installation of the @larksuite/cli package, which is the official CLI for a well-known collaboration platform.\n- [COMMAND_EXECUTION]: The skill performs shell command execution using the lark-cli binary to manage Lark Bases and perform data synchronization tasks.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from a local vault file to determine its operational logic.\n
  • Ingestion points: The file 99_Meta/structure-doctrine.md is accessed in references/vault-note.md to define formatting and filing protocols.\n
  • Boundary markers: The skill does not employ delimiters or ignore-instructions for the contents of the doctrine file.\n
  • Capability inventory: The skill possesses capabilities for command execution via lark-cli and file system modification through the vault note writing process.\n
  • Sanitization: There is no evidence of sanitization for data read from the vault configuration.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 29, 2026, 04:32 AM
Security Audit — agent-trust-hub — breakthrough-performance-db-setup