skills/broomva/skills/dogfood/Gen Agent Trust Hub

dogfood

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill analyzes local repository configuration files (e.g., Cargo.toml, package.json, app.json) and external reference documents (dogfood-patterns.md) to determine project characteristics and testing strategies. \n
  • Ingestion points: The detect_stack function in scripts/dogfood.sh and the Phase 2 loading logic in SKILL.md. \n
  • Boundary markers: None. The skill lacks explicit delimiters or instructions to ignore embedded commands within the ingested configuration files. \n
  • Capability inventory: The skill prompts the agent to execute shell commands using curl, jq, cliclick, screencapture, osascript, and agent-browser. \n
  • Sanitization: Content from configuration files is used for stack detection without evidence of sanitization or validation.\n- [DYNAMIC_EXECUTION]: The skill dynamically generates execution recipes and bash snippets at runtime based on the detected environment (Next.js, Tauri, Expo, etc.). These scripts are intended for immediate execution by the agent to verify the application deployment.\n- [COMMAND_EXECUTION]: The skill instructs the agent to execute system tools such as osascript and cliclick for UI automation, screencapture for visual evidence, and curl for interacting with local development endpoints. It also references reading application state from localized configuration files like ~/.dev-app/engine.json.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 03:08 PM
Security Audit — agent-trust-hub — dogfood