gateguard

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the gateguard-ai Python package via pip. This is an external dependency provided by a community author and is not associated with a trusted vendor or well-known service.
  • [COMMAND_EXECUTION]: The documentation requires running the command gateguard init to generate a local configuration file (.gateguard.yml) and initialize the tool's environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill's logic requires the agent to "Quote the user's current instruction verbatim" as part of its multi-stage gate process (Edit, Write, and Bash gates).
  • Ingestion points: The gate prompts in SKILL.md process live user instructions as part of the mandatory investigation criteria.
  • Boundary markers: Absent; the instructions do not define delimiters (like triple backticks or specific tags) or provide "ignore embedded instructions" warnings for the repeated user content.
  • Capability inventory: The skill controls access to file editing, file creation, and destructive Bash commands (including rm -rf, git reset --hard, and drop table).
  • Sanitization: While the skill recommends using redacted or synthetic values when investigating data files, it lacks sanitization or validation mechanisms for the user instructions it requires the agent to quote.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:40 PM
Security Audit — agent-trust-hub — gateguard