skill-review

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions and shell scripts for auditing the file system. These include using find to identify broken symlinks, ln -s for creating canonical links, and a project-specific CLI tool (joelclaw) to send events and ensure skill integrity. These operations are limited to specific local directories related to the agent's configuration.
  • [INDIRECT_PROMPT_INJECTION]: The skill describes an automated process ('Skill Garden') that ingests system state and local files like AGENTS.md to perform content audits.
  • Ingestion points: Reads AGENTS.md and checks file system patterns for stale architecture references.
  • Boundary markers: None explicitly defined in the provided markdown, though it functions as a diagnostic tool.
  • Capability inventory: Involves file system reads (find, read), repository management (git), and symlink creation (ln -s).
  • Sanitization: None detected in the documentation; however, the skill is intended for trusted administrative use within a managed repository.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 05:03 PM
Security Audit — agent-trust-hub — skill-review