skills/liustack/vibemaster/snapshot/Gen Agent Trust Hub

snapshot

Pass

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection by instructing the agent to 'trust the decisions' and 'inherit settled decisions directly' from restoration snapshots without reopening them. This allows potentially untrusted content in local files to influence agent logic.\n
  • Ingestion points: The agent reads task state from .issues/<YYYY-MM-DD-topic>/snapshot.md.\n
  • Boundary markers: The instructions lack explicit delimiters or safety warnings to ignore embedded directives within the snapshot content.\n
  • Capability inventory: The agent typically possesses shell access, file system permissions, and tool execution capabilities which could be leveraged if the snapshot content is malicious.\n
  • Sanitization: There is no process defined to sanitize or validate the recorded state before the agent acts upon it.\n- [COMMAND_EXECUTION]: The skill directs the agent to programmatically modify the repository's local git configuration by appending to .git/info/exclude. While this is a common local development pattern, it involves automated writes to version control metadata.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 15, 2026, 08:38 AM
Security Audit — agent-trust-hub — snapshot