close-thread
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [SAFE]: No security issues were detected. The skill operates on local project files using standard system utilities and follows a structured validation workflow for all modifications. All external vendor resources associated with the skill author are consistent with normal functionality.
- [INDIRECT_PROMPT_INJECTION]: The skill processes "delta documents" and implementation reports from thread folders to update project-wide documentation and agent instructions, creating a surface for indirect injection.
- Ingestion points: The
delta/directory andreport.mdfiles within the target thread folder as defined inSKILL.md. - Boundary markers: Edits require literal matching of existing text and verification of the target file's git blob hash according to
references/formats/delta-document.md. - Capability inventory: The skill can create, edit, or delete files in
docs/adr/,docs/pdr/,docs/glossary.md, and project agents files (AGENTS.md/CLAUDE.md). It also uses shell utilities includinggit,wc,grep, andprintffor data processing and metadata updates. - Sanitization: Implements a 1,000-word budget for agents files and a requirement to verify that passages remain semantically true after landing, as described in
SKILL.md. - [PROMPT_INJECTION]: The skill contains instructions for the agent to proceed with file modifications without additional user confirmation once preliminary checks are successful.
- Evidence: "Once the checks pass, the writes run without questions." in
SKILL.md. - [COMMAND_EXECUTION]: The skill utilizes local shell commands for repository introspection, file validation, and log management.
- Evidence: Usage of
git ls-files,git hash-object,wc -w,git log,git diff,grep, andprintffor file operations and validation throughout the skill body and instructions.
Audit Metadata