starworkInit

Pass

Audited by Gen Agent Trust Hub on Jun 25, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute specific shell commands including starwork init, starwork adapt, and starwork doctor. These commands are used to apply project blueprints, adapt for different AI hosts (like Claude Code or Cursor), and perform health checks on the initialized environment.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface when processing existing projects. It reads content from user-controlled files to integrate existing project rules into the new StarWork structure.
  • Ingestion points: Reads existing files such as README.md, AGENTS.md, and CLAUDE.md within the target project directory.
  • Boundary markers: The skill does not specify the use of clear delimiters or instructions for the agent to ignore potentially malicious content within these existing files when performing integration.
  • Capability inventory: The agent has the capability to write files (blueprints, rules) and execute local CLI tools (starwork).
  • Sanitization: No explicit sanitization or filtering of the content read from external project files is mentioned.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 25, 2026, 01:35 PM
Security Audit — agent-trust-hub — starworkInit