skill-stocktake
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill evaluates content from external skill files using a subagent, creating a surface where malicious instructions in those files could deceive the auditor or bias result outcomes. 1. Ingestion points: Metadata extraction in
scripts/scan.shand full file content reading by the Phase 2 subagent. 2. Boundary markers: The prompt uses[INVENTORY]and[CHECKLIST]labels to delimit data, which provides structural separation but not adversarial protection. 3. Capability inventory: Local file-read/write for caching and subagent invocation with search capabilities. 4. Sanitization: No explicit escaping or filtering is applied to the ingested content. - [COMMAND_EXECUTION]: The skill executes provided local bash scripts (
scan.sh,quick-diff.sh,save-results.sh) to perform file system operations, metadata extraction, and result management.
Audit Metadata