skills/mintuz/skills/decision-trace/Gen Agent Trust Hub

decision-trace

Pass

Audited by Gen Agent Trust Hub on Jul 23, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection (Category 8) as it is designed to ingest and process untrusted external content.
  • Ingestion points: SKILL.md specifies that the agent should read primary conversations, decision records, specifications, issues, and pull requests.
  • Boundary markers: There are no explicit instructions to use delimiters or to ignore nested instructions within the source documents.
  • Capability inventory: The skill requires the agent to trace production paths and run verification checks on the local environment.
  • Sanitization: No sanitization or validation of external content is requested.
  • [COMMAND_EXECUTION]: Step 4 of the SKILL.md file instructs the agent to "run the smallest decisive checks available" to verify implementation status. When combined with the processing of untrusted data, this instruction could be exploited to trick the agent into executing malicious commands found within source documents or transcripts.
  • [NO_CODE]: This skill consists entirely of markdown instructions and configuration settings. It does not provide any scripts, binaries, or executable code, which limits its inherent risk profile.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 23, 2026, 08:06 AM
Security Audit — agent-trust-hub — decision-trace