hrt-dark-mode-opt-in
Pass
Audited by Gen Agent Trust Hub on Aug 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill enables a mode where the agent makes autonomous decisions across multiple project phases including discovery, alignment, and implementation without stopping for user confirmation. This increases the risk surface where untrusted data within the project could influence the agent to take autonomous actions.
- Ingestion points: The skill affects how findings are resolved during proposal, specs, design, and implementation stages.
- Boundary markers: The skill mandates a specific prototype warning and requires the user to explicitly name the desired variant before activation.
- Capability inventory: The skill permits the agent to make autonomous decisions and proceed to automated code implementation during the 'apply' phase.
- Sanitization: No technical sanitization of codebase content is mentioned; safety relies on user acknowledgement of the risk of codebase damage.
- [PROMPT_INJECTION]: The skill provides instructions that override the standard agent behavior of requesting user confirmation for significant actions. By directing the agent to 'decide alone' and 'not stop', it fundamentally alters safety protocols and oversight mechanisms.
- [COMMAND_EXECUTION]: The '+implementation' variant allows the agent to automatically proceed to code application, which involves executing operations to modify the project's codebase without a manual review checkpoint.
Audit Metadata