bootstrap-agents-md

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill reads existing AGENTS.md and CLAUDE.md files found in the workspace to "preserve material intent" when drafting replacements. This creates an indirect prompt injection surface where a malicious user could commit directives to those files that are subsequently adopted by the skill and written into the new persistent agent context.
  • Ingestion points: SKILL.md (Step 1.3) instructs the agent to read existing root instruction files as evidence.
  • Boundary markers: The instructions do not define strict delimiters or include "ignore embedded instructions" warnings when processing the source evidence; they explicitly prioritize preserving the perceived intent.
  • Capability inventory: The skill involves writing new configuration files (AGENTS.md, CLAUDE.md) to the repository root.
  • Sanitization: No automated sanitization or safety-filtering is applied to the content extracted from the existing instruction files.
  • [COMMAND_EXECUTION]: The package includes scripts like scripts/test_skill.py that use subprocess.run() to execute other internal Python scripts for validation and testing purposes. Additionally, SKILL.md (Step 5.4) instructs the agent to execute a local validation script during its workflow.
  • [DYNAMIC_EXECUTION]: The file scripts/test_validate_agents_md.py uses importlib.util to dynamically load and execute the validate_agents_md.py module from a local path at runtime.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 10:51 AM
Security Audit — agent-trust-hub — bootstrap-agents-md