ai-ready
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill implements a 'PR Review & Convention Mining' procedure that fetches comments from merged Pull Requests using the
ghCLI tool. These external comments are untrusted and could contain malicious instructions designed to influence the agent's behavior. Furthermore, theai-ready.tsscript includes a sanitization pass that decodes URL-encoded payloads from files matching patterns like[[ORCA_RICH_MD:...]]or[cursor:.... This processing of untrusted external content represents a vulnerability surface if the agent subsequently treats the extracted text as authoritative instructions. - Ingestion points: GitHub CLI output for PR review mining; file contents read during the
--sanitizepass inscripts/ai-ready.ts. - Boundary markers: The
templates/.agents/standards/security-vibeguard.mdfile contains an 'Untrusted Tool Output Defense' protocol, instructing the agent to treat external content as data and disregard any embedded directives. - Capability inventory: The skill has
run_command(viabash) andwrite_to_filecapabilities, which are used for scaffolding and sanitization. - Sanitization: The
unwrapSyntheticArtifactsfunction inscripts/ai-ready.tsdecodes URL-encoded payloads usingdecodeURIComponentbut does not filter the resulting text for malicious prompt injection patterns. - [COMMAND_EXECUTION]: The skill relies on executing shell commands via the
bashtool. Specifically, thescripts/ai-ready.tsscript usesspawnSyncto verify the presence of modern CLI utilities (such asfd,rg, andbat) on the host system.SKILL.mdalso describes using theghCLI for mining repository history and conventions. These operations are intended for auditing repository state but involve executing external binaries. - [EXTERNAL_DOWNLOADS]: The skill utilizes the GitHub CLI (
gh) to fetch remote repository metadata, including PR reviews and comments. While these are standard developer operations, they involve pulling potentially unsafe data from external sources into the agent's reasoning context. - [PROMPT_INJECTION]: The skill defines core operating rules in
templates/.agents/standards/execution-kernel.mdusing instructions such as 'These rules override everything else when in conflict.' Additionally,SKILL.mdcontains control flow instructions like 'Stop execution immediately. Do not burn tokens explaining what was skipped' to optimize performance. The safety mandates insecurity-vibeguard.mdalso use patterns such as 'disregard prior instructions' as a defensive measure against malicious injection attempts in external data.
Audit Metadata