qstack-loop-trequartista

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external, potentially untrusted data from the repository (plans, board files, and execution records) which could contain malicious instructions designed to influence the agent's behavior.
  • Ingestion points: Reads files such as plan.html, plan.md, board-events.js, and board-protocol.md from the project directory.
  • Boundary markers: The instructions do not define clear delimiters or escaping mechanisms to separate untrusted plan content from agent instructions.
  • Capability inventory: The agent is authorized to execute shell commands (tests, builds, linters) and launch subagents based on the contents of these files.
  • Sanitization: There are no instructions for validating or sanitizing the content of repository files before they are used to influence execution logic or passed to subagents.
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute arbitrary shell commands defined within the repository for testing and building the project.
  • Evidence: Instructions explicitly direct the agent to "Run the repository's relevant tests, linters, type checks, builds, and focused behavioral checks."
  • This poses a security risk if the repository being processed contains malicious code within its test suite or build configuration.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 10:26 AM