skills/ingpoc/skills/operate/Gen Agent Trust Hub

operate

Pass

Audited by Gen Agent Trust Hub on Jun 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill's 'Research' phase uses WebSearch and WebFetch to retrieve content from external websites, which is then processed and stored as insights used for autonomous project updates.\n- [COMMAND_EXECUTION]: The skill uses the Bash tool to execute local Python scripts (bin/eval-score.py, bin/scan.py) and Node.js build commands (npx vite build) autonomously.\n- [PROMPT_INJECTION]: The instructions include directives such as 'EXECUTE this skill now' and 'Do NOT describe, summarize, or explain', which are designed to bypass user interaction and transparency in autonomous loops.\n- [COMMAND_EXECUTION]: Indirect Prompt Injection Surface: The skill establishes a workflow where untrusted data from the web (via WebFetch) can influence autonomous file modifications (Write) and script executions (Bash). Ingestion point: WebFetch. Boundary markers: None. Capability inventory: Bash, Write, Agent. Sanitization: None.\n- [DATA_EXFILTRATION]: Accesses files using hardcoded absolute Windows paths (C:/Users/gurusharan.gupta/Agents/Claude Code/...), which reveals specific user directory structures and targets a specific workstation identity.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 15, 2026, 09:45 AM
Security Audit — agent-trust-hub — operate