sync-horizon

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from an external repository (../eve-horizon) including git commit messages and plan documentation to synthesize prompts for sub-agents (workers). Malicious content embedded in these sources could influence the agent's behavior.
  • Ingestion points: Sibling repository ../eve-horizon (specifically docs/plans/, git logs, and CLI packages).
  • Boundary markers: Absent. No specific delimiters or safety instructions are used to wall off external content.
  • Capability inventory: Shell execution (git, ls, head, cat) and file write/edit operations across the local repository.
  • Sanitization: Absent. No validation or filtering is performed on extracted text before it is used to generate worker instructions.
  • [COMMAND_EXECUTION]: The skill performs extensive shell command execution against the local file system (using cd ../eve-horizon). These operations allow the skill to read files outside its own directory root, assuming a specific environment structure and allowing potential directory traversal if the sibling path is compromised.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 07:51 AM
Security Audit — agent-trust-hub — sync-horizon