skill-tuning
Pass
Audited by Gen Agent Trust Hub on Sep 3, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
Bashtool to perform filesystem operations and execute platform-specific CLI commands. Evidence:action-init.mdandaction-apply-fix.mduseBashfor directory creation and recursive copying (cp -r) to manage backups.action-agy-analysis.mdandaction-analyze-requirements.mdexecute themaestro delegatecommand viaBashto perform deep semantic analysis using the Agy sub-agent. Mitigation: The skill asks the user to specify the target path inaction-init.mdand includes anescapeForShellfunction to sanitize inputs before command construction.- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the target skill's codebase and interpolates it into prompts sent to sub-agents. Ingestion points:action-init.md(reads metadata fromSKILL.md),action-diagnose-*actions (read all markdown files in the target skill path). Boundary markers: Prompts use structured sections such as[CONTEXT],[TASK], and[EXPECTED]to delimit user-provided content from instructions. Capability inventory: The skill possessesBash,Write, andAgent(delegation) tools. Sanitization: Employs a basic shell escaping function (escapeForShell) when constructing CLI commands containing target content.- [DYNAMIC_EXECUTION]: The orchestrator dynamically selects and executes actions from thephases/actions/directory based on the current session state. Evidence:phases/orchestrator.mdcontains logic to read action markdown files and execute them via theAgentexecutor. It also implements dynamic file modification inaction-apply-fix.mdto inject diagnostic markers and code changes into target files.
Audit Metadata