executive

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The using-galyarder-framework sub-skill employs highly coercive language ('ABSOLUTELY MUST', 'not negotiable', 'not optional') to force the agent to adopt its protocols. It explicitly instructs the agent that framework skills should override default system prompt behavior, which is a pattern associated with behavior-modifying prompt injections.
  • [INDIRECT_PROMPT_INJECTION]: The skill framework explicitly handles untrusted data from the web (via BrowserOS) and provides guidelines for redacting sensitive information. Ingestion points: External web content retrieved via the BrowserOS tool and documents stored in docs/departments/Executive/. Boundary markers: The skill mentions that external data is 'treated as hostile' and instructs agents to 'Redact secrets/PII before sharing context'. Capability inventory: The agent has capabilities for shell command execution (via rtk proxy), file modification in the docs/ directory, and dispatching sub-agents. Sanitization: No specific code-based sanitization or escaping is implemented; the skill relies on high-level instructions to the LLM to filter content.
  • [EXTERNAL_DOWNLOADS]: The framework recommends the installation and use of several Model Context Protocol (MCP) servers, including Linear, BrowserOS, Context7, and RTK. These tools are used to proxy shell commands, track issues, and interact with the browser. While these are mostly well-known productivity services, they represent external dependencies required for the skill's full operation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 07:36 AM
Security Audit — agent-trust-hub — executive