skills/decisionnerd/dev-skills/agents/Gen Agent Trust Hub

agents

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes potentially untrusted data such as logs, transcripts, and execution traces from other agents to perform diagnostic autopsies.
  • Ingestion points: The references/analyze.md file directs the agent to gather 'runtime evidence' from external transcripts, run IDs, and logs (e.g., Langfuse, PostHog, OTel).
  • Capability inventory: The skill possesses capabilities to modify the local file system (git checkout, git status) and interact with remote workflow engines (Trigger.dev, CI jobs).
  • Sanitization: No specific sanitization or filtering protocols are defined for the ingested log data.
  • Boundary markers: The instructions do not explicitly mandate the use of delimiters or 'ignore' instructions when processing external agent traces.
  • [DYNAMIC_EXECUTION]: The skill implements a delegation pattern where it generates dynamic instructions for subagents to execute bounded tasks.
  • Mechanism: The sub / sub-agents functionality involves creating a 'parent brief' that dictates goals and constraints for child agents.
  • Safeguards: The skill includes defensive rules to prevent overlapping write ownership, mandates explicit 'done-when' criteria, and includes an emergency 'slap' protocol to cancel children that exhibit looping behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 11:26 PM
Security Audit — agent-trust-hub — agents