dead-letter

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the bash tool to perform Precondition Checks and execute commands listed in reproduction test packs. This allows for arbitrary shell command execution as part of the task recovery process.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted external data, including error logs, stderr, and subagent output, to generate Retry Packets. There is a risk that malicious instructions embedded in these error signals could be interpolated into new agent prompts without sufficient sanitization or boundary markers.
  • Ingestion points: SKILL.md Step 1 (error logs, terminal stderr, subagent exit messages).
  • Boundary markers: Absent. The record template in references/record-schema.md uses standard markdown sections but lacks specific delimiters to isolate untrusted error content from instructions.
  • Capability inventory: bash (command execution), write_to_file (file modification).
  • Sanitization: Absent. The skill instructions do not specify filtering or escaping of ingested error signals before including them in retry prompts.
  • [DYNAMIC_EXECUTION]: The skill generates executable reproduction test packs (e.g., .ts files for bun test) at close-out for deterministic failures. These scripts are dynamically created based on the agent's interpretation of the failure and are intended to be executed to verify fixes.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 09:27 PM
Security Audit — agent-trust-hub — dead-letter