skills/dailybothq/pocdd-skill/pocdd/Gen Agent Trust Hub

pocdd

Pass

Audited by Gen Agent Trust Hub on Jul 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The pocdd-work sub-skill facilitates the autonomous execution of Proof of Concept scripts (e.g., Python or JavaScript) within the .pocs/ directory to validate implementation findings and close investigation gaps. This behavior is consistent with the skill's primary purpose as a development tool.
  • [EXTERNAL_DOWNLOADS]: The pocdd-create sub-skill can fetch content from external URLs to distill goals and requirements when bootstrapping a new POC. This enables the agent to gather context from documentation or issue trackers.
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface because it ingests data from external sources (URLs, issues) to seed its internal task lists. The methodology mitigates this risk by requiring the agent to organize knowledge into structured sections (Goal, Implementation, Gaps) rather than executing raw external content.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 15, 2026, 09:37 PM
Security Audit — agent-trust-hub — pocdd