dead-letter
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the
bashtool to performPrecondition Checksand execute commands listed in reproduction test packs. This allows for arbitrary shell command execution as part of the task recovery process. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted external data, including error logs,
stderr, and subagent output, to generateRetry Packets. There is a risk that malicious instructions embedded in these error signals could be interpolated into new agent prompts without sufficient sanitization or boundary markers. - Ingestion points:
SKILL.mdStep 1 (error logs, terminal stderr, subagent exit messages). - Boundary markers: Absent. The record template in
references/record-schema.mduses standard markdown sections but lacks specific delimiters to isolate untrusted error content from instructions. - Capability inventory:
bash(command execution),write_to_file(file modification). - Sanitization: Absent. The skill instructions do not specify filtering or escaping of ingested error signals before including them in retry prompts.
- [DYNAMIC_EXECUTION]: The skill generates executable reproduction test packs (e.g.,
.tsfiles forbun test) at close-out for deterministic failures. These scripts are dynamically created based on the agent's interpretation of the failure and are intended to be executed to verify fixes.
Audit Metadata