secretary-controller

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external evidence such as logs, file content, and URL citations to construct decision memos. These ingestion points could potentially be used to introduce malicious instructions intended to influence the agent's synthesis. \n
  • Ingestion points: External file paths, test logs, and URL citations processed during the evidence snapshot phase (SKILL.md Step 1). \n
  • Boundary markers: The skill implements an Evidence Register and uses specific markers like [NO-DATA] or [CONTRADICTION] to handle uncertainties and contradictions. \n
  • Capability inventory: The skill utilizes bash, view_file, write_to_file, and replace_file_content to execute approved payloads. \n
  • Sanitization: The workflow relies on a mandatory cryptographic SHA-256 hash approval gate, requiring the user to verify the exact payload before any mutation occurs. \n- [DYNAMIC_EXECUTION]: The skill facilitates the generation and subsequent execution of a Payload Manifest, which can include shell scripts or file modifications. Evidence: SKILL.md Step 4 and agents/openai.yaml Step 5. This is the intended purpose of the skill and is protected by the hash verification mechanism. \n- [COMMAND_EXECUTION]: The skill uses the bash tool to calculate checksums and execute the final approved mutations. Evidence: SKILL.md Step 3 and 4. This behavior is gated by the cryptographic approval process to prevent unauthorized command execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 05:54 AM
Security Audit — agent-trust-hub — secretary-controller