skills/kirkchen/beat/explore/Gen Agent Trust Hub

explore

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external data from the project workspace, which could contain malicious instructions.
  • Ingestion points: Processes project artifacts located in beat/changes/ (specifically proposal.md, features/*.feature, design.md, and tasks.md).
  • Boundary markers: The instructions do not define clear delimiters or 'ignore' directives when interpolating the content of these external files into the agent's context.
  • Capability inventory: According to SKILL.md, the skill can read files, search the codebase, and write to markdown documentation files. It is explicitly forbidden from writing application code, which limits the potential impact of an injection.
  • Sanitization: There is no evidence of validation or sanitization for the ingested document content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 04:34 AM
Security Audit — agent-trust-hub — explore