decay

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands, specifically the mv command, to relocate hypothesis files between project directories (e.g., moving files from .fpf/knowledge/L2/ to .fpf/knowledge/L1/) when a decision is deprecated.
  • [INDIRECT_PROMPT_INJECTION]: The skill identifies an attack surface by ingesting and processing untrusted data from project files to drive its logic.
  • Ingestion points: The agent reads the valid_until and hypothesis_id fields from the frontmatter of all files located in .fpf/evidence/ and .fpf/knowledge/ directories.
  • Boundary markers: No explicit boundary markers or instructions to ignore embedded commands within the processed files are present.
  • Capability inventory: The skill possesses the capability to read files, write new markdown records, and execute file moves (mv) via the shell.
  • Sanitization: The skill lacks explicit sanitization or validation of the metadata fields retrieved from files before they are presented in reports or used as arguments in shell commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 01:10 AM
Security Audit — agent-trust-hub — decay