secretary

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill manages a data ingestion surface that is susceptible to indirect prompt injection, though it includes significant logical guardrails to mitigate this risk.
  • Ingestion points: The skill processes untrusted data during Step 0 (Intake Triage), Step 1 (Evidence Ingestion), and when aggregating outputs from delegated subagents.
  • Boundary markers: The protocol utilizes specific tags like [NO-DATA] and [CONTRADICTION] to logically separate and highlight uncertain or conflicting external data within the decision memo.
  • Capability inventory: The agent has access to bash, view_file, write_to_file, and replace_file_content to perform its tasks.
  • Sanitization: The skill enforces a mandatory Socratic Adversarial Gate (requiring three counter-arguments) and a two-stage review process, which serves as a defensive filtration layer for all ingested data.
  • [COMMAND_EXECUTION]: The skill utilizes the system shell to perform cryptographic verification of proposed actions.
  • Evidence: The procedure in SKILL.md and the Staff Work Doctrine instructs the agent to use bash and sha256sum to generate hashes of execution payloads. This is a controlled and legitimate use of command execution intended to prevent unauthorized or accidental modifications to the filesystem.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 09:23 PM
Security Audit — agent-trust-hub — secretary