skills/johnbortotti/skills/run-qc/Gen Agent Trust Hub

run-qc

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input from QC_<date>.md files and translates them into actions, creating a surface where malicious instructions in the plan could influence agent behavior.
  • Ingestion points: Reads and executes items from local QC_<date>.md files.
  • Boundary markers: The skill explicitly instructs the agent to 'Prove the boundary' and verify that credentials are 'absent, not merely forbidden,' providing a logical security check.
  • Capability inventory: Access to browser automation, system logs, and shell command execution.
  • Sanitization: No specific technical sanitization (e.g., escaping or delimiter wrapping) is mentioned for the content of the QC plan before it is processed by tools.
  • [COMMAND_EXECUTION]: The skill instructions explicitly direct the agent to 'run commands' and 'drive the product' as part of the QC process, which is a powerful capability that requires careful oversight when driven by external documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 02:26 AM
Security Audit — agent-trust-hub — run-qc