skill-stocktake

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill evaluates content from external skill files using a subagent, creating a surface where malicious instructions in those files could deceive the auditor or bias result outcomes. 1. Ingestion points: Metadata extraction in scripts/scan.sh and full file content reading by the Phase 2 subagent. 2. Boundary markers: The prompt uses [INVENTORY] and [CHECKLIST] labels to delimit data, which provides structural separation but not adversarial protection. 3. Capability inventory: Local file-read/write for caching and subagent invocation with search capabilities. 4. Sanitization: No explicit escaping or filtering is applied to the ingested content.
  • [COMMAND_EXECUTION]: The skill executes provided local bash scripts (scan.sh, quick-diff.sh, save-results.sh) to perform file system operations, metadata extraction, and result management.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:41 PM
Security Audit — agent-trust-hub — skill-stocktake