starworkDoctor
Pass
Audited by Gen Agent Trust Hub on Jun 25, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill is designed to interact with the
starworkCLI tool to perform environment diagnostics and workspace upgrades. It executes commands such asstarwork doctor --jsonandstarwork upgrade --dry-run. These commands are strictly scoped to the skill's primary purpose of workspace management and utilize the tool's built-in safety flags to prevent unintended modifications. - [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface because it reads and processes external, potentially untrusted project files including
README.md,CLAUDE.md, and.cursorrules(Ingestion points:SKILL.mdStep 2). The skill mitigates this by providing a specific 'Rules Extraction Guide' that requires the agent to classify and提炼 (refine) findings into structured categories rather than blindly trusting the input (Sanitization:references/rules-extraction-guide.md). The capability inventory is limited to local filesystem reads and execution of the specificstarworkCLI utility (Capability inventory:SKILL.md,Step 1andStep 7). No explicit XML-style boundary markers are present in the provided templates, but the logic enforces human-in-the-loop confirmation before any action (Boundary markers: User confirmation required inStep 6).
Audit Metadata