bootstrap-agents-md
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill reads existing
AGENTS.mdandCLAUDE.mdfiles found in the workspace to "preserve material intent" when drafting replacements. This creates an indirect prompt injection surface where a malicious user could commit directives to those files that are subsequently adopted by the skill and written into the new persistent agent context. - Ingestion points:
SKILL.md(Step 1.3) instructs the agent to read existing root instruction files as evidence. - Boundary markers: The instructions do not define strict delimiters or include "ignore embedded instructions" warnings when processing the source evidence; they explicitly prioritize preserving the perceived intent.
- Capability inventory: The skill involves writing new configuration files (
AGENTS.md,CLAUDE.md) to the repository root. - Sanitization: No automated sanitization or safety-filtering is applied to the content extracted from the existing instruction files.
- [COMMAND_EXECUTION]: The package includes scripts like
scripts/test_skill.pythat usesubprocess.run()to execute other internal Python scripts for validation and testing purposes. Additionally,SKILL.md(Step 5.4) instructs the agent to execute a local validation script during its workflow. - [DYNAMIC_EXECUTION]: The file
scripts/test_validate_agents_md.pyusesimportlib.utilto dynamically load and execute thevalidate_agents_md.pymodule from a local path at runtime.
Audit Metadata