skills/cursor/plugins/blast-radius/Gen Agent Trust Hub

blast-radius

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to create and run scripts or tests against the local codebase to prove safety facts and identify potential regressions.
  • Evidence: The 'How sure are you' section (Step 4: 'You ran it') and the 'Steps' section (Step 5: 'Write a script or test that runs the real code, run it').
  • [DYNAMIC_EXECUTION]: The instructions guide the agent to generate and execute code at runtime to verify logic and reproduce issues.
  • Evidence: 'Prove the one fact. Write a script or test that runs the real code, run it, and paste what happened.'
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted external data such as pull request diffs, commits, and third-party library source code, which could contain malicious instructions aimed at the agent.
  • Ingestion points: The agent ingests PR diffs, commits, and external library source code as specified in Step 1 and Step 3.
  • Boundary markers: No explicit boundary markers or 'ignore' instructions are provided for the data being analyzed.
  • Capability inventory: The agent has the capability to write files and execute commands to run the verification tests.
  • Sanitization: No explicit sanitization or filtering of the ingested code content is mentioned.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 10:44 PM
Security Audit — agent-trust-hub — blast-radius