skills/cursor/plugins/dyl-mode/Gen Agent Trust Hub

dyl-mode

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data from repository-local files and external design assets, creating a surface for potential instructions to influence agent behavior.\n
  • Ingestion points: The skill reads repository-local files such as AGENTS.md and .cursor/rules/, as well as design frames via Figma URLs.\n
  • Boundary markers: Absent; the skill does not specify delimiters or warnings to ignore commands within the ingested text.\n
  • Capability inventory: The agent can modify files, create and update pull requests via gh or origin CLI tools, and execute UI tests through the cursor-team-kit.\n
  • Sanitization: Absent; the skill lacks explicit validation or filtering logic for the content read from external or local sources.\n- [COMMAND_EXECUTION]: The skill employs command-line tools like gh pr and origin pr for lifecycle management of pull requests. A strict 'Dylan gate' is implemented that forbids merging or enabling auto-merge without explicit human authorization during the current interaction turn.\n- [EXTERNAL_DOWNLOADS]: The instructions require the use of external plugins including pstack, cursor-team-kit, thermos, and figma. These dependencies are identified as vendor-related resources necessary for the operational flow described in the skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 01:00 AM
Security Audit — agent-trust-hub — dyl-mode