just-do
Pass
Audited by Gen Agent Trust Hub on Sep 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and execute logic from an external 'Manifest' file provided via a path. Because the agent is instructed to use 'full autonomy' to ensure all 'Acceptance Criteria' and 'Global Invariants' hold, a malicious manifest could contain instructions that trick the agent into performing unauthorized actions.
- Ingestion points: The file specified by
<manifest-path>inSKILL.md. - Boundary markers: Absent. The agent is instructed to read the manifest in full and treat it as a binding contract.
- Capability inventory: The agent is granted 'full autonomy', which includes file system operations (logging to
~/.manifest-dev/logs/), Git operations (origin/main...HEAD), and the ability to decide 'how' to reach the goal state. - Sanitization: Absent. There are no instructions to validate or sanitize the content of the manifest before execution.
- [COMMAND_EXECUTION]: The instructions explicitly grant the agent autonomy to determine the method of execution ('how is yours') to achieve the manifest's goals. This implies the agent may execute shell commands, scripts, or modify files across the system to satisfy the criteria defined in the external manifest.
Audit Metadata