muse-security
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses run_command and bash to perform security diagnostics (e.g., rpm -qa, dpkg -l) and configuration management (Ansible) within a structured procedure that emphasizes non-destructive diagnostic capture and dry-run verification.
- [INDIRECT_PROMPT_INJECTION]: As a security audit tool, the skill naturally ingests untrusted data such as source code and diagnostic bundles. 1. Ingestion points: Source code files and lockfiles in references/sast.md; diagnostic bundles and package identifiers in references/cve.md. 2. Boundary markers: The skill uses a strict mode-based routing system defined in SKILL.md to limit the agent's context to a specific task. 3. Capability inventory: The agent has access to bash, run_command, view_file, and write_to_file tools across all reference playbooks. 4. Sanitization: The skill implements the Vibeguard Protocol and Zero-Secret Isolation in references/runtime.md, which involves regex masking of secrets in logs and out-of-band secret injection.
- [SAFE]: Static detection of destructive commands (e.g., rm -rf /) in references/runtime.md is a false positive; the skill documentation lists these patterns specifically to instruct the agent to intercept and block them, acting as a security guardrail rather than an attack vector.
Audit Metadata