entropy-management
Pass
Audited by Gen Agent Trust Hub on Jun 16, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute a local script using the command
node scripts/hooks/dispatcher.cjs stop. This is used to run automated sensors for codebase health checks. - [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection as it processes various files from the repository to identify drift and regressions.
- Ingestion points: The agent reads contents from
CLAUDE.md, thedocs/directory, and session-specific metadata within.orchestration/. - Boundary markers: Absent; there are no specified delimiters or instructions to prevent the agent from obeying commands found within the scanned data.
- Capability inventory: The skill can execute local Node.js scripts and write to the file system, including updating documentation and project memory.
- Sanitization: Absent; there is no explicit validation or escaping of the content read from the repository files before processing.
Audit Metadata