skills/m1nga/skills/coffee-brewing/Gen Agent Trust Hub

coffee-brewing

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input from user-provided photos (beans, bags, shots) and text-based taste reports to generate brewing recommendations. It also persists data to local files, creating an attack surface where manipulated inputs or local state files could influence agent behavior.
  • Ingestion points: Processes visual data from photos and user feedback; reads configuration and history from ~/.coffee/hardware.md and ~/.coffee/beans.md (SKILL.md).
  • Boundary markers: Absent. The skill does not use specific delimiters or instructions to ignore potential commands embedded within the vision-parsed data or local file content.
  • Capability inventory: Performs read and write operations to the local file system within the ~/.coffee/ directory (SKILL.md).
  • Sanitization: Absent. There is no evidence of filtering or validation of the data extracted from images or stored in local files before it is used to construct prompts for the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 05:59 AM
Security Audit — agent-trust-hub — coffee-brewing