gardener
Pass
Audited by Gen Agent Trust Hub on Oct 4, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses various shell commands to manage the software stack, including
pnpmfor package inspection and installation,gitfor log analysis and version control, andrg(ripgrep) for searching. It also executes a project-specific script./scripts/vendor-agent-sources.shto refresh source mirrors. - [INDIRECT_PROMPT_INJECTION]: The skill includes a workflow step where it identifies and "studies" external public repositories (via the
find-peersskill) to learn from their implementation patterns. This ingestion of untrusted external content represents a potential injection surface. - Ingestion points: External code repositories discovered by the
find-peersskill and listed in.brain/resources/peers.svx. - Boundary markers: None identified in the instructions to separate external peer code from internal task instructions.
- Capability inventory: The agent has the ability to execute shell commands (
pnpm,git,turbo), modify local project files (bumping versions inpackage.json), and create new test/lint files in the repository. - Sanitization: There are no mentioned mechanisms for sanitizing or filtering instructions that might be embedded in the code or documentation of the studied peer repositories.
Audit Metadata