ico-your-internals

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests untrusted Markdown files from a target directory and executes user-defined prompts from a question bank.
  • Ingestion points: The scripts/run.sh script identifies and ingests all Markdown files within a user-specified --target directory. The scripts/ask-loop.py script reads and executes questions defined in an external YAML --bank file.
  • Boundary markers: The SKILL.md instructions explicitly define the target documents as read-only and restrict writes to a dedicated local cache directory (~/.cache/ico-your-internals/).
  • Capability inventory: The skill possesses the ability to execute shell commands (to run the ico CLI) and write files to both the local cache and the project repository (for rendering results).
  • Sanitization: The scripts/render-summary.py script utilizes a regex-based SECRET_PATTERNS filter to detect and redact API keys (e.g., Anthropic keys) and authorization tokens from the generated public evidence bundle.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 04:23 PM
Security Audit — agent-trust-hub — ico-your-internals