skills/ericrisco/rsc-harness/orient/Gen Agent Trust Hub

orient

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill functions as a guidance layer that formats the agent's output into a consistent summary block (the 'brújula'). It does not possess capabilities to execute arbitrary code or access sensitive system resources.
  • [EXTERNAL_DOWNLOADS]: The evaluation cases (evals/cases.yaml) mention the use of npx @ericrisco/rsc, which is a command-line utility provided by the skill author ('ericrisco'). This is a legitimate vendor resource used for setting up project components.
  • [INDIRECT_PROMPT_INJECTION]: The skill reads project state and user preferences from 02-DOCS/wiki/harness/user-profile.md to customize its responses. While this represents a data ingestion surface, the skill lacks tool access or execution capabilities that could be abused via injected instructions.
  • Ingestion points: Reads profile files and the repository file system to determine project status.
  • Boundary markers: The skill uses a structured 'brújula block' format to separate its orientation content.
  • Capability inventory: No tools, subprocesses, or network operations are defined in this skill.
  • Sanitization: Not applicable as the skill does not pass this data to executable sinks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 11:10 PM
Security Audit — agent-trust-hub — orient