ai-ready

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill implements a 'PR Review & Convention Mining' procedure that fetches comments from merged Pull Requests using the gh CLI tool. These external comments are untrusted and could contain malicious instructions designed to influence the agent's behavior. Furthermore, the ai-ready.ts script includes a sanitization pass that decodes URL-encoded payloads from files matching patterns like [[ORCA_RICH_MD:...]] or [cursor:.... This processing of untrusted external content represents a vulnerability surface if the agent subsequently treats the extracted text as authoritative instructions.
  • Ingestion points: GitHub CLI output for PR review mining; file contents read during the --sanitize pass in scripts/ai-ready.ts.
  • Boundary markers: The templates/.agents/standards/security-vibeguard.md file contains an 'Untrusted Tool Output Defense' protocol, instructing the agent to treat external content as data and disregard any embedded directives.
  • Capability inventory: The skill has run_command (via bash) and write_to_file capabilities, which are used for scaffolding and sanitization.
  • Sanitization: The unwrapSyntheticArtifacts function in scripts/ai-ready.ts decodes URL-encoded payloads using decodeURIComponent but does not filter the resulting text for malicious prompt injection patterns.
  • [COMMAND_EXECUTION]: The skill relies on executing shell commands via the bash tool. Specifically, the scripts/ai-ready.ts script uses spawnSync to verify the presence of modern CLI utilities (such as fd, rg, and bat) on the host system. SKILL.md also describes using the gh CLI for mining repository history and conventions. These operations are intended for auditing repository state but involve executing external binaries.
  • [EXTERNAL_DOWNLOADS]: The skill utilizes the GitHub CLI (gh) to fetch remote repository metadata, including PR reviews and comments. While these are standard developer operations, they involve pulling potentially unsafe data from external sources into the agent's reasoning context.
  • [PROMPT_INJECTION]: The skill defines core operating rules in templates/.agents/standards/execution-kernel.md using instructions such as 'These rules override everything else when in conflict.' Additionally, SKILL.md contains control flow instructions like 'Stop execution immediately. Do not burn tokens explaining what was skipped' to optimize performance. The safety mandates in security-vibeguard.md also use patterns such as 'disregard prior instructions' as a defensive measure against malicious injection attempts in external data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 09:23 PM
Security Audit — agent-trust-hub — ai-ready