skill-tuning

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the Bash tool to perform filesystem operations and execute platform-specific CLI commands. Evidence: action-init.md and action-apply-fix.md use Bash for directory creation and recursive copying (cp -r) to manage backups. action-agy-analysis.md and action-analyze-requirements.md execute the maestro delegate command via Bash to perform deep semantic analysis using the Agy sub-agent. Mitigation: The skill asks the user to specify the target path in action-init.md and includes an escapeForShell function to sanitize inputs before command construction.- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the target skill's codebase and interpolates it into prompts sent to sub-agents. Ingestion points: action-init.md (reads metadata from SKILL.md), action-diagnose-* actions (read all markdown files in the target skill path). Boundary markers: Prompts use structured sections such as [CONTEXT], [TASK], and [EXPECTED] to delimit user-provided content from instructions. Capability inventory: The skill possesses Bash, Write, and Agent (delegation) tools. Sanitization: Employs a basic shell escaping function (escapeForShell) when constructing CLI commands containing target content.- [DYNAMIC_EXECUTION]: The orchestrator dynamically selects and executes actions from the phases/actions/ directory based on the current session state. Evidence: phases/orchestrator.md contains logic to read action markdown files and execute them via the Agent executor. It also implements dynamic file modification in action-apply-fix.md to inject diagnostic markers and code changes into target files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 12:15 PM