create-status-surface

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill performs local command execution to verify environment connectivity with its dependencies.
  • Evidence: The tau-doctor command in scripts/create_status_surface.py invokes a sibling skill's entrypoint (tau/run.sh) using subprocess.run with a list-based command argument to prevent shell injection.
  • The execution is non-mutating and is restricted to local diagnostic checks within the vendor's own ecosystem.
  • [PROMPT_INJECTION]: The skill manages a potential indirect prompt injection surface by ingesting machine-readable progress data and rendering it into human-readable formats.
  • Ingestion points: Data is read from files specified by the --input flag in scripts/create_status_surface.py.
  • Boundary markers: The skill automatically generates comprehensive claims and fail_closed_on metadata in its outputs to clearly define its scope and prevent agents from assuming unauthorized capabilities.
  • Capability inventory: The skill is restricted to reading/writing local files and executing the local tau wrapper script.
  • Sanitization: Input labels and IDs are escaped using html.escape before being rendered into the HTML status surface to mitigate cross-site scripting risks and unintended instruction parsing.
  • [DATA_EXPOSURE]: Analysis confirms the skill only accesses user-provided file paths and the local /tmp directory for report generation.
  • No hardcoded credentials, sensitive system paths, or network exfiltration patterns were detected in the source code or build scripts.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:01 PM
Security Audit — agent-trust-hub — create-status-surface