secretary
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill manages a data ingestion surface that is susceptible to indirect prompt injection, though it includes significant logical guardrails to mitigate this risk.
- Ingestion points: The skill processes untrusted data during
Step 0(Intake Triage),Step 1(Evidence Ingestion), and when aggregating outputs from delegated subagents. - Boundary markers: The protocol utilizes specific tags like
[NO-DATA]and[CONTRADICTION]to logically separate and highlight uncertain or conflicting external data within the decision memo. - Capability inventory: The agent has access to
bash,view_file,write_to_file, andreplace_file_contentto perform its tasks. - Sanitization: The skill enforces a mandatory Socratic Adversarial Gate (requiring three counter-arguments) and a two-stage review process, which serves as a defensive filtration layer for all ingested data.
- [COMMAND_EXECUTION]: The skill utilizes the system shell to perform cryptographic verification of proposed actions.
- Evidence: The procedure in
SKILL.mdand theStaff Work Doctrineinstructs the agent to usebashandsha256sumto generate hashes of execution payloads. This is a controlled and legitimate use of command execution intended to prevent unauthorized or accidental modifications to the filesystem.
Audit Metadata