dyl-mode
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data from repository-local files and external design assets, creating a surface for potential instructions to influence agent behavior.\n
- Ingestion points: The skill reads repository-local files such as
AGENTS.mdand.cursor/rules/, as well as design frames via Figma URLs.\n - Boundary markers: Absent; the skill does not specify delimiters or warnings to ignore commands within the ingested text.\n
- Capability inventory: The agent can modify files, create and update pull requests via
ghororiginCLI tools, and execute UI tests through thecursor-team-kit.\n - Sanitization: Absent; the skill lacks explicit validation or filtering logic for the content read from external or local sources.\n- [COMMAND_EXECUTION]: The skill employs command-line tools like
gh prandorigin prfor lifecycle management of pull requests. A strict 'Dylan gate' is implemented that forbids merging or enabling auto-merge without explicit human authorization during the current interaction turn.\n- [EXTERNAL_DOWNLOADS]: The instructions require the use of external plugins includingpstack,cursor-team-kit,thermos, andfigma. These dependencies are identified as vendor-related resources necessary for the operational flow described in the skill.
Audit Metadata