hodman

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFECREDENTIALS_UNSAFECOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill facilitates the retrieval of sensitive information using the hodman env get and hodman git secret commands with the --unsafe flag. This allows access to environment variables (e.g., API keys) and private keys in the project environment.\n
  • Evidence: The 'Secret reveal' section in SKILL.md explicitly details the use of the --unsafe flag for these operations.\n
  • Mitigations: The skill instructs the agent to never print, persist, or summarize these secrets in tasks, threads, or reports.\n- [COMMAND_EXECUTION]: The agent is granted the ability to execute arbitrary shell commands and SQL queries within the project's environment, which is a powerful capability.\n
  • Evidence: Commands such as hodman shell exec and hodman sql query are documented for use in diagnostic and operational tasks.\n- [DATA_EXFILTRATION]: The skill provides tools for reading project files, querying databases, and accessing environment variables, establishing a capability for data extraction.\n
  • Evidence: hodman file get, hodman sql query, and hodman env get are core features of the toolset.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes data from untrusted external sources, which could contain malicious instructions designed to influence the agent's behavior.\n
  • Ingestion points: Project logs (hodman logs), source code via file cat, and incoming messages from external channels like Telegram via thread send (reading the thread history).\n
  • Boundary markers: The skill does not define specific delimiters or "ignore" instructions for processing these data streams.\n
  • Capability inventory: The agent has high-privilege capabilities including shell exec, file put, sql query, and env get across the project environment.\n
  • Sanitization: While safety warnings are provided regarding credential handling, there is no technical sanitization specified for content ingested from external sources before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 11:02 PM
Security Audit — agent-trust-hub — hodman