skills/microsoft/hve-core/rpi-quick/Gen Agent Trust Hub

rpi-quick

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFEDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • Durable File Tracking: The skill utilizes a .copilot-tracking/ directory to manage task state, research, and plans. While this involves writing to the local file system, it is a structured approach for maintaining context across sessions and does not involve sensitive user directories.
  • Indirect Task Input: The skill ingests task descriptions from conversation history and attached files. This represents a standard surface for indirect prompt injection where external data might influence agent behavior. The skill includes 'Quality Gates' and 'Stop Rules' to mitigate risks by requiring validation and human intervention for product decisions.
  • Subagent and Tool Execution: The orchestrator sequences calls to other sub-skills and tools. This is a common pattern for complex agent workflows, and the skill specifies that tools should only be used as a fallback for the smallest safe scope, aligning with the principle of least privilege.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 09:46 AM
Security Audit — agent-trust-hub — rpi-quick