show-me-your-work
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes a local bash script (
scripts/log.sh) to perform file append operations and ensure log formatting. - [INDIRECT_PROMPT_INJECTION]: The skill audits its own actions by reading interaction transcripts from
agent-transcripts/. While transcripts could contain instructions from external data processed by the agent, the skill actively mitigates risks by sanitizing output. - Ingestion points: The skill reads file content from the
agent-transcripts/directory as specified inSKILL.md. - Boundary markers: No specific text delimiters are defined for the transcript content, though the audit logic uses logical checkpoints (run start/end) to isolate relevant content.
- Capability inventory: The skill executes a local shell script (
scripts/log.sh) and writes to local TSV files. - Sanitization: The
scripts/log.shutility implements formula injection mitigation by prefixing characters like=,+,-, and@with a single quote and stripping newline, tab, and carriage return characters. - [DATA_EXFILTRATION]: The skill accesses sensitive agent interaction history from
agent-transcripts/. However, it includes explicit instructions to avoid globbing across unrelated project directories (~/.cursor/projects/*/) to prevent unauthorized access to private chats, limiting the scope to the current run.
Audit Metadata