parent-project-skills

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • Dynamic Instruction Discovery: The skill directs the agent to locate and load additional SKILL.md files from a parent directory (e.g., ../../.opencode/skills/*/SKILL.md). This behavior allows the agent's operational logic to be dynamically extended at runtime based on the file system structure. While intended for cross-repo development, this mechanism relies on the integrity of the discovered files.
  • Information Boundary Enforcement: The skill contains detailed instructions to prevent the leakage of proprietary or internal information from a parent project into the public-facing workerd repository. This is a defensive measure designed to maintain data privacy during cross-boundary tasks.
  • Indirect Prompt Injection Surface: By reading external markdown files into its context, the agent is exposed to potential instructions embedded in those files.
  • Ingestion points: ../../.opencode/skills/*/SKILL.md and ../../AGENTS.md (SKILL.md)
  • Boundary markers: The skill includes an 'Information Boundary' section that warns against leaking internal data, though it does not provide specific delimiters for the ingested content itself.
  • Capability inventory: The agent uses a Read tool to ingest the content of discovered files into its reasoning context.
  • Sanitization: No explicit sanitization or validation of the ingested markdown content is mentioned beyond the agent's general reasoning instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 04:03 PM
Security Audit — agent-trust-hub — parent-project-skills