hodman
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFECREDENTIALS_UNSAFECOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill facilitates the retrieval of sensitive information using the
hodman env getandhodman git secretcommands with the--unsafeflag. This allows access to environment variables (e.g., API keys) and private keys in the project environment.\n - Evidence: The 'Secret reveal' section in
SKILL.mdexplicitly details the use of the--unsafeflag for these operations.\n - Mitigations: The skill instructs the agent to never print, persist, or summarize these secrets in tasks, threads, or reports.\n- [COMMAND_EXECUTION]: The agent is granted the ability to execute arbitrary shell commands and SQL queries within the project's environment, which is a powerful capability.\n
- Evidence: Commands such as
hodman shell execandhodman sql queryare documented for use in diagnostic and operational tasks.\n- [DATA_EXFILTRATION]: The skill provides tools for reading project files, querying databases, and accessing environment variables, establishing a capability for data extraction.\n - Evidence:
hodman file get,hodman sql query, andhodman env getare core features of the toolset.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes data from untrusted external sources, which could contain malicious instructions designed to influence the agent's behavior.\n - Ingestion points: Project logs (
hodman logs), source code viafile cat, and incoming messages from external channels like Telegram viathread send(reading the thread history).\n - Boundary markers: The skill does not define specific delimiters or "ignore" instructions for processing these data streams.\n
- Capability inventory: The agent has high-privilege capabilities including
shell exec,file put,sql query, andenv getacross the project environment.\n - Sanitization: While safety warnings are provided regarding credential handling, there is no technical sanitization specified for content ingested from external sources before it is processed by the agent.
Audit Metadata