skills/grahama1970/agent-skills/tau/Gen Agent Trust Hub

tau

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill's main script, scripts/tau_skill.py, utilizes subprocess.run to invoke local command-line tools including git, gh (GitHub CLI), uv, and crontab. These operations are used to gather repository status, interact with GitHub issues, and manage workflow lifecycles, which is consistent with the skill's primary purpose as a development harness.
  • [PERSISTENCE_MECHANISMS]: The skill monitors persistence by inspecting the local system's crontab via crontab -l in the watchdog_status_payload function. This check ensures the project's watchdog monitor is active and reporting receipts as expected.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill reads and writes state artifacts, such as receipt.json and manifest.json, to local directories including ${HOME}/workspace/experiments/tau and ${HOME}/.local/state/project-watchdog. These actions are used to maintain execution state and verify proof boundaries for agentic workflows.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a surface for indirect prompt injection as it processes structured data from external project artifacts.
  • Ingestion points: The scripts/tau_skill.py script reads and parses JSON artifacts from the local tau project directory.
  • Boundary markers: None explicitly implemented in the logic, but the SKILL.md instructions emphasize the requirement for continuous JSON-stream monitoring for verification.
  • Capability inventory: The skill facilitates command execution through the tau CLI wrapper using subprocess.run.
  • Sanitization: The skill processes structured JSON data from its own associated project to generate status reports and orchestrate subagent tasks.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:00 PM
Security Audit — agent-trust-hub — tau