skills/imraywang/rayskills/ray-thread/Gen Agent Trust Hub

ray-thread

Pass

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill contains well-defined instructions that restrict the agent to a 'Material Archeology' and 'Structure Selection' workflow, ensuring it only processes provided information without performing unauthorized actions.
  • [SAFE]: The 'Iron Rule: No Ghostwriting' constraint provides a logic-based safety mechanism that prevents the agent from generating deceptive or synthetic opinions, requiring all narrative 'voice' to be provided by the human user.
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection attack surface because it is designed to ingest and parse content from external files (e.g., markdown retrospectives) provided by the user. While this is the intended purpose of the tool, there are no specific instructions to the agent to disregard hidden commands within that ingested data.
  • Ingestion points: The skill processes text and file content from paths provided in the user prompt (e.g., ~/projects/xxx/RETRO.md in SKILL.md).
  • Boundary markers: Absent; the instructions do not use delimiters or explicit 'ignore embedded instructions' warnings for external file content.
  • Capability inventory: Filesystem read access is utilized to extract material for the thread skeleton (SKILL.md).
  • Sanitization: No specific sanitization or validation of the ingested file content is performed before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 20, 2026, 04:54 PM
Security Audit — agent-trust-hub — ray-thread