skills/guangzan/monorail/rail-setup/Gen Agent Trust Hub

rail-setup

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill explicitly directs the agent to operate without user oversight for critical actions, stating "never pause to ask the user to confirm the plan" and "Write immediately after presenting — no confirmation, no waiting for edits."
  • [INDIRECT_PROMPT_INJECTION]: The agent is instructed to read and process potentially untrusted content from existing repository files such as AGENTS.md, CLAUDE.md, and documents within the docs/monorail/ directory. This creates an ingestion point for instructions that could influence the agent's autonomous writing phase.
  • [INDIRECT_PROMPT_INJECTION]: The skill automates the modification of files that govern agent behavior (CLAUDE.md or AGENTS.md) and documentation structure without incorporating sanitization logic or boundary markers for the data ingested from the repository environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 03:26 AM
Security Audit — agent-trust-hub — rail-setup