skills/mikevalstar/okq/okq-maintain/Gen Agent Trust Hub

okq-maintain

Pass

Audited by Gen Agent Trust Hub on Jul 24, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill focuses on documentation maintenance and structural integrity using a local CLI tool. No suspicious network activity, data exfiltration patterns, or obfuscation techniques were detected.
  • [COMMAND_EXECUTION]: The skill instructions involve executing the okq tool and running code snippets or commands described in documentation to verify their accuracy against the implementation. These actions are limited to the development environment and the intended audit process.
  • [PROMPT_INJECTION]: The skill ingests data from external documentation files during semantic audits, which represents a surface for indirect prompt injection.
  • Ingestion points: Documentation assertions and content retrieved via okq get and the Read tool in SKILL.md.
  • Boundary markers: None explicitly present to delimit document content from instructions.
  • Capability inventory: The skill has access to Bash, Read, and Edit tools, allowing it to execute commands and modify files.
  • Sanitization: The skill mitigates risk by instructing the agent to confirm all discrepancies and proposed documentation fixes with the user before applying any changes.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 24, 2026, 07:08 AM
Security Audit — agent-trust-hub — okq-maintain