idea-refine
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze data from user input ($ARGUMENTS) and the project codebase (using Glob, Grep, and Read tools). This is a standard attack surface for agents that process untrusted content.
- Ingestion points: Processes user-provided ideas and reads local project files to provide context (SKILL.md).
- Capability inventory: The agent has capabilities to read files, execute a local initialization script, and write markdown artifacts to the
docs/ideas/directory (SKILL.md, scripts/idea-refine.sh). - Boundary markers: The skill uses a structured three-phase process (Understand, Evaluate, Sharpen) which helps guide the agent and isolate the analysis phase from artifact creation.
- Sanitization: The skill does not perform technical sanitization of input but uses a conversational confirmation loop before performing file writes.
- [COMMAND_EXECUTION]: The skill includes a local initialization script (
scripts/idea-refine.sh) used for directory setup. The script is restricted to basic directory creation (mkdir -p) and does not perform network operations or access sensitive system paths.
Audit Metadata