create-status-surface
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill performs local command execution to verify environment connectivity with its dependencies.
- Evidence: The
tau-doctorcommand inscripts/create_status_surface.pyinvokes a sibling skill's entrypoint (tau/run.sh) usingsubprocess.runwith a list-based command argument to prevent shell injection. - The execution is non-mutating and is restricted to local diagnostic checks within the vendor's own ecosystem.
- [PROMPT_INJECTION]: The skill manages a potential indirect prompt injection surface by ingesting machine-readable progress data and rendering it into human-readable formats.
- Ingestion points: Data is read from files specified by the
--inputflag inscripts/create_status_surface.py. - Boundary markers: The skill automatically generates comprehensive
claimsandfail_closed_onmetadata in its outputs to clearly define its scope and prevent agents from assuming unauthorized capabilities. - Capability inventory: The skill is restricted to reading/writing local files and executing the local
tauwrapper script. - Sanitization: Input labels and IDs are escaped using
html.escapebefore being rendered into the HTML status surface to mitigate cross-site scripting risks and unintended instruction parsing. - [DATA_EXPOSURE]: Analysis confirms the skill only accesses user-provided file paths and the local
/tmpdirectory for report generation. - No hardcoded credentials, sensitive system paths, or network exfiltration patterns were detected in the source code or build scripts.
Audit Metadata