skills/lee-to/ai-factory/aif-archive/Gen Agent Trust Hub

aif-archive

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill ingests content from project-managed plan files to determine task completion. While this presents an indirect prompt injection surface, the risk is minimal due to the specific task-parsing logic and restricted file-management actions. Ingestion points: Plan files in .ai-factory/plans/ and ROADMAP.md. Boundary markers: Uses ## Tasks headers and specific checkbox patterns. Capability inventory: Uses Bash for mv and mkdir, and Edit for metadata updates. Sanitization: Employs strict matching for - [x] and - [ ] patterns.
  • [COMMAND_EXECUTION]: Employs Bash for mv, mkdir, and git log operations. These tools are used appropriately for local archiving and version history retrieval within the project sandbox.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 12:02 PM
Security Audit — agent-trust-hub — aif-archive