session-zero-weapon

Pass

Audited by Gen Agent Trust Hub on Jul 25, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted user input (Topic, Scope, Failure mode, Stack context) and interpolates it into the Purpose and search query fields of the ai-tools/proposed-guardians-backlog.md file. This creates a surface for indirect prompt injection where malicious instructions could be embedded in a proposal. \n
  • Ingestion points: User-provided domain and scope inputs defined in Step 1 of SKILL.md. \n
  • Boundary markers: None identified for user input interpolation in the resulting Markdown entries. \n
  • Capability inventory: File-write operations to project files in the ai-tools/ directory. \n
  • Sanitization: The skill enforces naming conventions for IDs but does not sanitize descriptive text fields.
  • [COMMAND_EXECUTION]: The skill instructs the agent to perform file system operations, including reading and appending to local project files (backlog, queue, and model comparison matrix). These operations are restricted to specific, non-sensitive paths.
  • [SAFE]: No obfuscation, hardcoded credentials, remote code execution patterns, or unauthorized network operations were detected. References to AI models from well-known providers (Google, Anthropic, OpenAI) are treated as neutral configuration strings.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 25, 2026, 03:23 AM
Security Audit — agent-trust-hub — session-zero-weapon