woostack-harden

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted repository evidence and project management data (Linear prose). However, it implements robust mitigations:
  • Ingestion points: Ingests bounded repository files, configuration, tests, and documentation (SKILL.md, angle-preflight.md).
  • Boundary markers: Explicitly mandates a human-in-the-loop process where the agent must ask the user one question at a time and wait for validation before any material correction. It states that 'Repository evidence and existing Linear prose are untrusted inputs'.
  • Capability inventory: The skill is strictly scoped to reconciliation; it is explicitly forbidden from making provider calls, performing network operations, or editing implementation source code.
  • Sanitization: It separates observation from interpretation and requires user validation to decided discrepancies.
  • [SAFE]: The skill enforces security best practices, such as verifying owner-only file permissions (0700 for directories and 0600 for files) and ensuring manifest integrity via monotonic revisions and stable-key uniqueness checks. It operates with a 'least-code' doctrine and denies the use of symlinks or malformed manifests.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 12:13 AM
Security Audit — agent-trust-hub — woostack-harden