skills/joelhooks/rat-stack/gardener/Gen Agent Trust Hub

gardener

Pass

Audited by Gen Agent Trust Hub on Oct 4, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses various shell commands to manage the software stack, including pnpm for package inspection and installation, git for log analysis and version control, and rg (ripgrep) for searching. It also executes a project-specific script ./scripts/vendor-agent-sources.sh to refresh source mirrors.
  • [INDIRECT_PROMPT_INJECTION]: The skill includes a workflow step where it identifies and "studies" external public repositories (via the find-peers skill) to learn from their implementation patterns. This ingestion of untrusted external content represents a potential injection surface.
  • Ingestion points: External code repositories discovered by the find-peers skill and listed in .brain/resources/peers.svx.
  • Boundary markers: None identified in the instructions to separate external peer code from internal task instructions.
  • Capability inventory: The agent has the ability to execute shell commands (pnpm, git, turbo), modify local project files (bumping versions in package.json), and create new test/lint files in the repository.
  • Sanitization: There are no mentioned mechanisms for sanitizing or filtering instructions that might be embedded in the code or documentation of the studied peer repositories.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 4, 2026, 01:57 AM
Security Audit — agent-trust-hub — gardener