f1-test-drive

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill involves the execution of local shell commands and scripts (e.g., ./f1, bun run apps/f1/server.ts) to manage testing environments, start server processes, and interact with the system APIs.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines processes for ingesting user-provided input, such as issue descriptions and chat messages, into agent sessions.
  • Ingestion points: External data is accepted via command-line arguments such as --title, --description, and --text in the SKILL.md file.
  • Boundary markers: No delimiters or safety warnings for embedded instructions are identified in the protocol.
  • Capability inventory: The skill has the capability to execute local scripts, start server processes, and manage file system paths under /tmp and the agent's home directory.
  • Sanitization: There is no description of explicit sanitization, escaping, or validation of the input content prior to processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 01:50 PM
Security Audit — agent-trust-hub — f1-test-drive