skills/kkenny0/taku/taku-compact/Gen Agent Trust Hub

taku-compact

Pass

Audited by Gen Agent Trust Hub on May 7, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: Analysis of the skill instructions and associated files reveals no malicious patterns or high-risk behaviors. The skill's operations are confined to local file inspection and state summarization.
  • [COMMAND_EXECUTION]: The skill executes standard git commands to retrieve information about repository changes. This is used to gather evidence for the state scan and does not involve risky parameters or elevated privileges.
  • [PROMPT_INJECTION]: The skill processes content from various project files which constitutes an indirect prompt injection surface. However, the skill has no dangerous capabilities that could be exploited through this channel.
  • Ingestion points: Reads project metadata files (DESIGN.md, PLAN.md, etc.) and files within the .taku/ directory.
  • Boundary markers: No explicit delimiters or instructions are used to separate ingested file content from agent instructions.
  • Capability inventory: Operations are limited to reading local files, running git commands, and writing a markdown summary to a specific directory.
  • Sanitization: Content from project files is incorporated into the brief without specific sanitization filters.
Audit Metadata
Risk Level
SAFE
Analyzed
May 7, 2026, 07:20 AM
Security Audit — agent-trust-hub — taku-compact