skills/danangjoyoo/nerd/nerd-xfast/Gen Agent Trust Hub

nerd-xfast

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill contains instructions that suppress transparency and oversight, directing the agent to "Emit zero introductory text, internal thoughts, or progress updates" and "Do not talk before acting, expose thinking, or narrate reasoning." It further instructs the agent to "Continue without pausing for commentary or confirmation until every Goal is reached," which effectively bypasses user review for intermediate actions and conceals the agent's decision-making process.
  • [COMMAND_EXECUTION]: The skill provides guidelines for batching shell commands (e.g., rg, grep, sed, awk, find, git) using the && operator. It also authorizes the creation of "multi-file patches" in a single, uninterrupted write sequence, granting the agent the capability to perform broad filesystem modifications without user verification between steps.
  • [INDIRECT_PROMPT_INJECTION]: The skill establishes an attack surface for indirect prompt injection by design.
  • Ingestion points: The agent is instructed to read files and discovery outputs from the environment to gain necessary context (SKILL.md).
  • Boundary markers: There are no instructions for using delimiters or warnings to ignore instructions embedded in the external content being read.
  • Capability inventory: The agent has access to powerful shell search/filter tools and the ability to modify multiple files.
  • Sanitization: The instructions do not mention any sanitization, validation, or filtering of content read from external files before it is used to influence agent behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 11:04 PM
Security Audit — agent-trust-hub — nerd-xfast