muse-security

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses run_command and bash to perform security diagnostics (e.g., rpm -qa, dpkg -l) and configuration management (Ansible) within a structured procedure that emphasizes non-destructive diagnostic capture and dry-run verification.
  • [INDIRECT_PROMPT_INJECTION]: As a security audit tool, the skill naturally ingests untrusted data such as source code and diagnostic bundles. 1. Ingestion points: Source code files and lockfiles in references/sast.md; diagnostic bundles and package identifiers in references/cve.md. 2. Boundary markers: The skill uses a strict mode-based routing system defined in SKILL.md to limit the agent's context to a specific task. 3. Capability inventory: The agent has access to bash, run_command, view_file, and write_to_file tools across all reference playbooks. 4. Sanitization: The skill implements the Vibeguard Protocol and Zero-Secret Isolation in references/runtime.md, which involves regex masking of secrets in logs and out-of-band secret injection.
  • [SAFE]: Static detection of destructive commands (e.g., rm -rf /) in references/runtime.md is a false positive; the skill documentation lists these patterns specifically to instruct the agent to intercept and block them, acting as a security guardrail rather than an attack vector.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 09:23 PM
Security Audit — agent-trust-hub — muse-security