show-me-your-work

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes a local bash script (scripts/log.sh) to perform file append operations and ensure log formatting.
  • [INDIRECT_PROMPT_INJECTION]: The skill audits its own actions by reading interaction transcripts from agent-transcripts/. While transcripts could contain instructions from external data processed by the agent, the skill actively mitigates risks by sanitizing output.
  • Ingestion points: The skill reads file content from the agent-transcripts/ directory as specified in SKILL.md.
  • Boundary markers: No specific text delimiters are defined for the transcript content, though the audit logic uses logical checkpoints (run start/end) to isolate relevant content.
  • Capability inventory: The skill executes a local shell script (scripts/log.sh) and writes to local TSV files.
  • Sanitization: The scripts/log.sh utility implements formula injection mitigation by prefixing characters like =, +, -, and @ with a single quote and stripping newline, tab, and carriage return characters.
  • [DATA_EXFILTRATION]: The skill accesses sensitive agent interaction history from agent-transcripts/. However, it includes explicit instructions to avoid globbing across unrelated project directories (~/.cursor/projects/*/) to prevent unauthorized access to private chats, limiting the scope to the current run.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 12:39 AM
Security Audit — agent-trust-hub — show-me-your-work