tk-drive
Pass
Audited by Gen Agent Trust Hub on Aug 12, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill performs local shell operations, primarily using Git commands like
git rev-parseandgit commit. It also orchestrates execution units that run focused verification checks, such as unit tests, within a repository environment. - [PROMPT_INJECTION]: The skill processes untrusted data from external sources like issues or tickets to define development tasks, posing a risk of indirect prompt injection. Mandatory Evidence Chain: 1) Ingestion points: External issues and source documents; 2) Boundary markers: Document status (Ready/Pending/Blocked) and lineage checks; 3) Capability inventory: Git commands, worker dispatch, and browser verification; 4) Sanitization: Resolution of ambiguities and mandatory user approval of execution plans.
Audit Metadata