tau
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill's main script,
scripts/tau_skill.py, utilizessubprocess.runto invoke local command-line tools includinggit,gh(GitHub CLI),uv, andcrontab. These operations are used to gather repository status, interact with GitHub issues, and manage workflow lifecycles, which is consistent with the skill's primary purpose as a development harness. - [PERSISTENCE_MECHANISMS]: The skill monitors persistence by inspecting the local system's
crontabviacrontab -lin thewatchdog_status_payloadfunction. This check ensures the project's watchdog monitor is active and reporting receipts as expected. - [DATA_EXPOSURE_AND_EXFILTRATION]: The skill reads and writes state artifacts, such as
receipt.jsonandmanifest.json, to local directories including${HOME}/workspace/experiments/tauand${HOME}/.local/state/project-watchdog. These actions are used to maintain execution state and verify proof boundaries for agentic workflows. - [INDIRECT_PROMPT_INJECTION]: The skill defines a surface for indirect prompt injection as it processes structured data from external project artifacts.
- Ingestion points: The
scripts/tau_skill.pyscript reads and parses JSON artifacts from the localtauproject directory. - Boundary markers: None explicitly implemented in the logic, but the
SKILL.mdinstructions emphasize the requirement for continuous JSON-stream monitoring for verification. - Capability inventory: The skill facilitates command execution through the
tauCLI wrapper usingsubprocess.run. - Sanitization: The skill processes structured JSON data from its own associated project to generate status reports and orchestrate subagent tasks.
Audit Metadata