domain-organization

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external, untrusted content from source code repositories, including instructions, manifests, and documentation.
  • Ingestion points: Target repository instructions, manifests (e.g., package.json, import maps), and source files are ingested from the working tree as described in SKILL.md.
  • Boundary markers: The instructions explicitly direct the agent to distinguish verified facts from proposed paths and reconcile evidence with the actual working tree in SKILL.md.
  • Capability inventory: The skill manages file moves, import updates, and build root modifications across the repository as detailed in SKILL.md.
  • Sanitization: No explicit sanitization or filtering of ingested instruction content is defined.
  • [EXTERNAL_DOWNLOADS]: The skill references specific integration points with external tooling packages in references/enforcement.md.
  • Evidence: References to @darkmatter/oxlint/organization and @darkmatter/dependency-cruiser.
  • Context: These packages are vendor-owned resources belonging to the skill author 'darkmatter'. The skill includes instructions that prohibit the agent from performing unauthorized installations or dependency upgrades.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:26 AM
Security Audit — agent-trust-hub — domain-organization