aim

Pass

Audited by Gen Agent Trust Hub on Jul 15, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes external data that could contain malicious instructions designed to influence the agent's behavior. This includes user-provided input via the $ARGUMENTS variable and configuration files such as .aim/state.json, aim.profile.yaml, and aim.roles.yaml.
  • Ingestion points: Command arguments ($ARGUMENTS) and local project files (.aim/state.json, aim.profile.yaml, aim.roles.yaml) which are read during the bootstrap phase.
  • Boundary markers: The skill does not employ explicit delimiters or system instructions to disregard potential commands embedded within the processed data.
  • Capability inventory: The agent is capable of orchestrating specialized subagents (aim-po, aim-tdo, aim-dev, and aim-reviewer) and executing lifecycle commands such as upgrade and replan.
  • Sanitization: No sanitization, validation, or escaping of the external content is performed before interpolation into the agent's context.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 15, 2026, 06:28 AM
Security Audit — agent-trust-hub — aim