idk-now

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from the repository and git history to formulate project vision and session goals, creating a surface for indirect instructions.
  • Ingestion points: SKILL.md and references/flow.md define a survey process that reads README.md, AGENTS.md, CLAUDE.md, PRODUCT.md, VISION.md, docs/, .productfeeling/, FEELING.md, and git log.
  • Boundary markers: No explicit delimiters or instructions are provided to the agent to ignore potentially malicious directions embedded within these project files during the survey phase.
  • Capability inventory: While the skill is primarily read-only (using tools like git log and find), it recommends the execution of other high-impact skills (such as fix-it, merge-it, ship-it, and repos) based on the analysis of the untrusted data.
  • Sanitization: The instructions do not define any sanitization, escaping, or validation of the ingested file content before it is used to influence the agent's decision-making logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 11:26 PM
Security Audit — agent-trust-hub — idk-now