resolve-beagle

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes potentially untrusted data from multiple sources which can influence the agent's output and file-writing behavior.
  • Ingestion points: The skill reads existing specification files from docs/specs/, performs grep/glob scans of the codebase, and fetches external content via web search and page fetch tools.
  • Boundary markers: There are no explicit instructions or delimiters defined to isolate or ignore malicious commands that might be embedded in the specification files or external web content.
  • Capability inventory: The skill possesses the ability to read, grep, glob, perform web search and page fetch, rewrite local files, and execute git commit commands.
  • Sanitization: No explicit sanitization or validation steps are described for the content retrieved from external research before it is proposed as a specification update.
  • [COMMAND_EXECUTION]: The skill is designed to interact with the repository's version control system.
  • Evidence: The workflow includes a step to git commit changes to the specification document, although this is gated by a user confirmation prompt.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 09:18 AM
Security Audit — agent-trust-hub — resolve-beagle