scaffold

Pass

Audited by Gen Agent Trust Hub on Aug 31, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches a documentation specification file from the vendor's official GitHub repository (raw.githubusercontent.com/horizon-foundry/foundry/main/reference/doc-set-spec.md) to define the structure of the scaffolded project.\n- [COMMAND_EXECUTION]: Executes a shell command to perform a daily version check. The command uses curl to query a vendor-specific API (foundry.thehorizonfoundry.com) and manages a rate-limit state file in the user's home directory (~/.claude/.foundry-version-checked).\n- [INDIRECT_PROMPT_INJECTION]: The skill seeds a 'resume rule' in the project's documentation (CLAUDE.md) that instructs the agent to read and follow instructions from a phase plan index in TODOS.md during future sessions. This creates a surface where external or malicious modifications to these project files could influence agent behavior.\n
  • Ingestion points: Reads project-specific plans and backlog from TODOS.md and associated plan files; fetches template specifications from a remote repository.\n
  • Boundary markers: The instructions do not specify any delimiters or safety markers to differentiate between data and instructions within the phase plan files.\n
  • Capability inventory: Shell execution (curl, find, mkdir, touch) and broad file system write access for project creation.\n
  • Sanitization: The skill does not describe mechanisms for sanitizing user-provided inputs or validating the integrity of instructions retrieved from phase plan files.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 31, 2026, 05:48 PM
Security Audit — agent-trust-hub — scaffold