starworkDoctor

Pass

Audited by Gen Agent Trust Hub on Jun 25, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill is designed to interact with the starwork CLI tool to perform environment diagnostics and workspace upgrades. It executes commands such as starwork doctor --json and starwork upgrade --dry-run. These commands are strictly scoped to the skill's primary purpose of workspace management and utilize the tool's built-in safety flags to prevent unintended modifications.
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface because it reads and processes external, potentially untrusted project files including README.md, CLAUDE.md, and .cursorrules (Ingestion points: SKILL.md Step 2). The skill mitigates this by providing a specific 'Rules Extraction Guide' that requires the agent to classify and提炼 (refine) findings into structured categories rather than blindly trusting the input (Sanitization: references/rules-extraction-guide.md). The capability inventory is limited to local filesystem reads and execution of the specific starwork CLI utility (Capability inventory: SKILL.md, Step 1 and Step 7). No explicit XML-style boundary markers are present in the provided templates, but the logic enforces human-in-the-loop confirmation before any action (Boundary markers: User confirmation required in Step 6).
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 25, 2026, 01:36 PM
Security Audit — agent-trust-hub — starworkDoctor