000-TnR-Absolute-Rigor

Pass

Audited by Gen Agent Trust Hub on Jun 5, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: The skill uses behavioral override instructions to alter the agent's default safety and helpfulness profile, specifically directing it to "suspend normal 'helpful assistant' behaviors (like guessing, politeness-over-truth, or shallow fixes)" and "switch to Forensic Engineering."
  • [PROMPT_INJECTION]: Employs role-play injection by instructing the agent to "Act as [Highest-Possible-Level Specialist]" (e.g., Red Team Lead) and adopts an authoritative tone ("Non-negotiable intensity", "Mandatory Execution Checklist") to bypass standard operational constraints.
  • [DATA_EXFILTRATION]: Mandates a process called "INTERNAL DEPLETION" which requires the agent to consume "Every byte of local code/git/logs." This creates a significant data exposure risk by directing the agent to read potentially sensitive information (PII, tokens, or environment details) that may reside in log files or git history.
  • [COMMAND_EXECUTION]: Instructs the agent to perform extensive filesystem and system operations including grep, git log, git blame, and reading arbitrary files to satisfy the "Absolute Rigor" requirements.
  • [EXTERNAL_DOWNLOADS]: The metadata includes an installation command that fetches the skill from GitHub via curl. As this targets a well-known service and repository for skill distribution, this specific action is considered standard configuration.
  • [INDIRECT_PROMPT_INJECTION]: The skill identifies a surface for indirect injection by mandating the ingestion of data from untrusted external sources like Stack Overflow and Reddit ("TRIAGED COMMUNITY") without specifying boundary markers or sanitization procedures for the processed content.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 5, 2026, 07:33 AM
Security Audit — agent-trust-hub — 000-TnR-Absolute-Rigor