rail-setup
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill explicitly directs the agent to operate without user oversight for critical actions, stating "never pause to ask the user to confirm the plan" and "Write immediately after presenting — no confirmation, no waiting for edits."
- [INDIRECT_PROMPT_INJECTION]: The agent is instructed to read and process potentially untrusted content from existing repository files such as
AGENTS.md,CLAUDE.md, and documents within thedocs/monorail/directory. This creates an ingestion point for instructions that could influence the agent's autonomous writing phase. - [INDIRECT_PROMPT_INJECTION]: The skill automates the modification of files that govern agent behavior (
CLAUDE.mdorAGENTS.md) and documentation structure without incorporating sanitization logic or boundary markers for the data ingested from the repository environment.
Audit Metadata