woostack-execute-overnight

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill instructions define a highly restricted execution environment. It mandates 'fixed execution loops', 'bounded review sweeps', and 'truthful handback' based on fresh reads from authoritative sources (Git, GitHub, Linear), which prevents state manipulation and ensures integrity.- [COMMAND_EXECUTION]: The skill includes shell scripts (tests/run-tests.sh, scripts/tests/run-tests.sh) and an inline Python script (scripts/tests/test-sweep-integrity-contract.sh) used exclusively for structural validation of the SKILL.md file. These scripts are benign and do not execute untrusted external code or perform risky system modifications.- [PROMPT_INJECTION]: While the skill processes external project data which is a surface for indirect prompt injection, it mitigates this by requiring explicit, pre-approved implementation plans and acyclic dependency graphs. It refuses to proceed if unresolved decisions requiring human judgment are detected, reducing the risk of autonomous obedience to embedded instructions.- [DATA_EXFILTRATION]: The skill accesses repository ancestry, PR state, and project metadata. These operations are essential for its purpose and are restricted to specific, well-known developer tools and services (GitHub, Graphite, Linear). No evidence of secret harvesting or unauthorized exfiltration to third-party domains was found.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 09:28 PM
Security Audit — agent-trust-hub — woostack-execute-overnight