he-research

Pass

Audited by Gen Agent Trust Hub on Jun 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill initiates a local shell script at scripts/runbooks/select-runbooks.sh during its workflow to dynamically select and apply runbooks based on the skill name.
  • [PROMPT_INJECTION]: The skill's primary function involves ingesting and processing data from external references and project documentation, which creates a vulnerability to indirect prompt injection attacks.
  • Ingestion points: The skill reads from external references, codebase patterns, and documentation files found in the docs/ directory.
  • Boundary markers: The instructions do not define specific delimiters or security warnings to prevent the agent from following instructions embedded within researched material.
  • Capability inventory: The skill has the ability to launch parallel subagents, execute local shell scripts, and perform file-write operations to documentation files.
  • Sanitization: No sanitization, validation, or escaping of external content is specified before it is processed by the agent or its subagents.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 19, 2026, 04:30 PM
Security Audit — agent-trust-hub — he-research