skills/maxgfr/skills/blueprint/Gen Agent Trust Hub

blueprint

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes a Node.js utility, scripts/peer-run.mjs, which coordinates cross-checks between different AI agent CLI tools (e.g., Claude and Codex). This script is implemented following security best practices: it uses child_process.spawn with shell: false and explicitly configures restricted permission modes and sandboxes for the peer agents, preventing them from writing to the filesystem or executing arbitrary commands.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests content from the repository during its 'Orient' and 'Crosscheck' phases, which exposes it to instructions potentially hidden in repository files. However, the skill implements a strict 'No repository claim without path:line' rule. The provided peer-run.mjs script automates the validation of these citations, verifying that quoted text exists in the file and ensuring that all paths are resolved within the repository root using realpathSync to prevent path traversal attacks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 06:04 AM
Security Audit — agent-trust-hub — blueprint