office-hours

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses shell commands like git log, git diff, and grep to understand the project context. These operations are limited to reading repository metadata and managing a documentation directory.\n- [EXTERNAL_DOWNLOADS]: The skill utilizes WebSearch to provide industry awareness. It follows best practices by implementing a privacy gate that requires user approval before sending any data to a search provider.\n- [PROMPT_INJECTION]: The skill has an indirect prompt injection surface as it processes untrusted data from the web and project files.\n
  • Ingestion points: External search results, CLAUDE.md, TODOS.md, and local design documents.\n
  • Boundary markers: None explicitly defined in the instructions.\n
  • Capability inventory: The skill has access to Bash and Write tools but is strictly limited by instructions to only produce design documentation and forbidden from writing code.\n
  • Sanitization: No explicit sanitization of external data is performed before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 05:19 PM
Security Audit — agent-trust-hub — office-hours