elite-ops
Pass
Audited by Gen Agent Trust Hub on Apr 18, 2026
Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill uses explicit override language: "This overrides passive assistant behavior with owner-engineer execution posture," which is a pattern used to bypass default safety or behavioral constraints.- [PROMPT_INJECTION]: The instructions mandate that the agent "move forward without asking permission when the repo can answer the question," which reduces human-in-the-loop oversight for file system and configuration changes.- [DATA_EXFILTRATION]: Under "Repo Findings," the agent is instructed to actively seek out sensitive architectural details including "Database, ORM, auth, permissions." While intended for development, this directs the agent to locate and process sensitive security schemas and potentially credentials.- [COMMAND_EXECUTION]: The execution protocol requires the agent to autonomously "Execute the actual changes," which includes "Migrations, API updates," and running "validation" such as tests or linting tools.- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection (Category 8). Ingestion points: The agent is directed to read and "assimilate" the entire codebase (SKILL.md). Boundary markers: None; the skill does not include delimiters or instructions to ignore embedded commands in the repo data. Capability inventory: File-write operations, API updates, and execution of validation/test scripts (SKILL.md). Sanitization: No validation or escaping of repository content is performed before it influences the agent's "Elite Ship Mode" posture.
Audit Metadata