skills/breakthrough-edu/breakthrough-meta-performance-skills/breakthrough-performance-db-setup/Gen Agent Trust Hub
breakthrough-performance-db-setup
Pass
Audited by Gen Agent Trust Hub on Aug 29, 2026
Risk Level: SAFECREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The files
references/template-and-teaching.mdandreferences/changing-the-base.mdinclude a hardcoded Lark Base token (Yt2WbfTeQa0tjQsjMUwlfaEvgXb). This token refers to a vendor-owned template intended for duplication by the student.\n- [EXTERNAL_DOWNLOADS]: The skill instructs the installation of the@larksuite/clipackage, which is the official CLI for a well-known collaboration platform.\n- [COMMAND_EXECUTION]: The skill performs shell command execution using thelark-clibinary to manage Lark Bases and perform data synchronization tasks.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from a local vault file to determine its operational logic.\n - Ingestion points: The file
99_Meta/structure-doctrine.mdis accessed inreferences/vault-note.mdto define formatting and filing protocols.\n - Boundary markers: The skill does not employ delimiters or ignore-instructions for the contents of the doctrine file.\n
- Capability inventory: The skill possesses capabilities for command execution via
lark-cliand file system modification through the vault note writing process.\n - Sanitization: There is no evidence of sanitization for data read from the vault configuration.
Audit Metadata