decay
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands, specifically the
mvcommand, to relocate hypothesis files between project directories (e.g., moving files from.fpf/knowledge/L2/to.fpf/knowledge/L1/) when a decision is deprecated. - [INDIRECT_PROMPT_INJECTION]: The skill identifies an attack surface by ingesting and processing untrusted data from project files to drive its logic.
- Ingestion points: The agent reads the
valid_untilandhypothesis_idfields from the frontmatter of all files located in.fpf/evidence/and.fpf/knowledge/directories. - Boundary markers: No explicit boundary markers or instructions to ignore embedded commands within the processed files are present.
- Capability inventory: The skill possesses the capability to read files, write new markdown records, and execute file moves (
mv) via the shell. - Sanitization: The skill lacks explicit sanitization or validation of the metadata fields retrieved from files before they are presented in reports or used as arguments in shell commands.
Audit Metadata