kb-path-instructions

Pass

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides comprehensive instructions for agents to ingest, analyze, and modify a wide variety of workspace files which could contain untrusted data.\n
  • Ingestion points: Instructions cover files matching **/*.{md,html,jsx,tsx,vue,svelte,astro,css,scss,less,py,js,ts,mjs,cjs}.\n
  • Boundary markers: While references/multi-agent-reliability.md defines structured output formats for findings and scores, it lacks specific instructions for delimiting or ignoring potentially malicious prompts embedded within the processed data.\n
  • Capability inventory: The instructions in references/powershell-terminal-ops.md and references/multi-agent-reliability.md guide the use of state-changing tools such as terminal command execution and file writing.\n
  • Sanitization: The skill does not provide specific guidance on sanitizing or validating the content of workspace files before they are processed by tools.\n- [COMMAND_EXECUTION]: The file references/powershell-terminal-ops.md contains detailed guidance and code snippets for executing shell commands, specifically targeting Git operations on Windows systems.\n
  • Evidence: The skill recommends a specific pattern using [IO.File]::WriteAllText(), git commit -F, and Remove-Item within a single run_in_terminal call to ensure reliable multi-line commits.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 26, 2026, 06:00 AM