skills/jcosta33/suspec/sus-inventory/Gen Agent Trust Hub

sus-inventory

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is intended to analyze "unfamiliar or change-critical code," which serves as a source of untrusted data that may contain malicious instructions directed at the agent.
  • Ingestion points: The agent reads local source code, file metadata, and configuration files throughout the workspace (SKILL.md).
  • Boundary markers: Absent. There are no instructions to use delimiters or to treat the analyzed content as potentially adversarial data that should be ignored if it contains instructions.
  • Capability inventory: The skill can read any file in the workspace, write to ~/.agents/artifacts/, execute commands for "safe checks," and delete files during the "Close" phase.
  • Sanitization: Absent. The skill does not specify any sanitization or validation of the code being analyzed before it is processed or recorded in artifacts.
  • [COMMAND_EXECUTION]: The methodology requires the agent to "Run safe checks for dynamic claims" and specifies that "no-match claims require command and result." This enables the execution of shell commands to verify the behavior of the code under analysis, which is risky if the code is malicious.
  • [DATA_EXFILTRATION]: The skill maps sensitive areas including "persistence, generated surfaces, configuration, and external consumers." This process inherently involves accessing and recording potentially sensitive information, such as credentials or environment variables, from configuration files.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 09:14 PM
Security Audit — agent-trust-hub — sus-inventory