phase-self-check

Pass

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill defines a process for ingesting untrusted data from user intent and phase observations to guide agent behavior. 1. Ingestion points: User intent and phase observations (SKILL.md). 2. Boundary markers: No delimiters or instructions are present to ignore embedded commands. 3. Capability inventory: The skill uses memory writing and local perl command execution (SKILL.md). 4. Sanitization: No validation or sanitization of external content is specified before interpolation.
  • [COMMAND_EXECUTION]: The skill suggests using a perl one-liner (perl -i -pe 's|old|new|g' files...) for bulk file edits. This constitutes a script generation pattern from templates based on the current task state.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 13, 2026, 02:53 PM
Security Audit — agent-trust-hub — phase-self-check