qstack-loop-trequartista
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external, potentially untrusted data from the repository (plans, board files, and execution records) which could contain malicious instructions designed to influence the agent's behavior.
- Ingestion points: Reads files such as
plan.html,plan.md,board-events.js, andboard-protocol.mdfrom the project directory. - Boundary markers: The instructions do not define clear delimiters or escaping mechanisms to separate untrusted plan content from agent instructions.
- Capability inventory: The agent is authorized to execute shell commands (tests, builds, linters) and launch subagents based on the contents of these files.
- Sanitization: There are no instructions for validating or sanitizing the content of repository files before they are used to influence execution logic or passed to subagents.
- [COMMAND_EXECUTION]: The skill instructs the agent to execute arbitrary shell commands defined within the repository for testing and building the project.
- Evidence: Instructions explicitly direct the agent to "Run the repository's relevant tests, linters, type checks, builds, and focused behavioral checks."
- This poses a security risk if the repository being processed contains malicious code within its test suite or build configuration.
Audit Metadata