review
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill requires running a local script
scripts/graph-auditduring the mandatory filing gate in Step 4 to verify the integrity of touched durable files. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from multiple sources including
log.md, initiative logs, and financial metrics to generate business scorecards. - Ingestion points: Data is ingested from
wiki/business/,log.md,baton.md, initiative logs, and immutable session receipts inraw/inbox/. - Boundary markers: The skill defines a 'durable claim admission gate' which requires re-opening cited files to verify exact passage existence and mandates the use of 'Founder-stated: unverified' labels for unconfirmed data.
- Capability inventory: The skill possesses the ability to write to business wiki files (
wiki/business/reviews/), update the global log (log.md), and execute local scripts. - Sanitization: Instructions strictly prohibit 'reconstructing from vibes' and require re-computing metrics formulas before filing, acting as a manual sanitization step for the agent.
Audit Metadata