coach

Pass

Audited by Gen Agent Trust Hub on Apr 2, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the Bash tool to perform file system operations, specifically for listing and sorting files in the coaching log directory to retrieve previous session data.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by reading data from various files in the user's vault (habits, OKRs, and projects). * Ingestion points: reference.md specifies reading from paths defined in coach-config.yaml. * Boundary markers: Absent; no instructions are provided to the agent to ignore or delimit instructions potentially embedded in the vault files. * Capability inventory: Bash and Write tools are available to the skill, posing a risk if injected instructions are executed. * Sanitization: No evidence of content validation or sanitization is present before the vault data is processed.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 2, 2026, 06:18 AM
Security Audit — agent-trust-hub — coach