skills/howells/skills/aperture/Gen Agent Trust Hub

aperture

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the local repository, including implementation files, usage examples, and configuration files. This data could contain malicious instructions designed to influence the agent's behavior during the extraction process.
  • Ingestion points: Source files, import sites, package manager configurations, and usage examples (SKILL.md, references/package-extraction.md).
  • Boundary markers: None present to distinguish between instructions and data within the processed files.
  • Capability inventory: The agent can move files, rewrite imports, and execute build/test/lint scripts (SKILL.md).
  • Sanitization: No explicit sanitization or filtering of the ingested content is mentioned.
  • [COMMAND_EXECUTION]: The skill instructions direct the agent to execute build, test, and lint scripts found within the repository to validate the new package (SKILL.md). While these are standard development tasks, executing scripts from a repository that may contain untrusted code is a known attack surface.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 02:15 AM
Security Audit — agent-trust-hub — aperture