taku-think
Pass
Audited by Gen Agent Trust Hub on May 7, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill operates as a requirement clarification tool, using internal logic and file writing to structure development tasks. It does not attempt to execute arbitrary code or exfiltrate sensitive information.\n- [PROMPT_INJECTION]: The skill processes project files and external website data during competitive research, which presents an indirect prompt injection surface.\n
- Ingestion points: Reads local project documents and fetches competitor UI information via web search.\n
- Boundary markers: No specific delimiters are used to wrap or isolate content fetched from external sources.\n
- Capability inventory: The skill can write files to the local filesystem and route tasks to other agent tools like /taku-plan and /taku-build.\n
- Sanitization: No explicit validation or filtering of external content is performed.
Audit Metadata