starworkInit
Pass
Audited by Gen Agent Trust Hub on Jun 25, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute specific shell commands including
starwork init,starwork adapt, andstarwork doctor. These commands are used to apply project blueprints, adapt for different AI hosts (like Claude Code or Cursor), and perform health checks on the initialized environment. - [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface when processing existing projects. It reads content from user-controlled files to integrate existing project rules into the new StarWork structure.
- Ingestion points: Reads existing files such as
README.md,AGENTS.md, andCLAUDE.mdwithin the target project directory. - Boundary markers: The skill does not specify the use of clear delimiters or instructions for the agent to ignore potentially malicious content within these existing files when performing integration.
- Capability inventory: The agent has the capability to write files (blueprints, rules) and execute local CLI tools (
starwork). - Sanitization: No explicit sanitization or filtering of the content read from external project files is mentioned.
Audit Metadata