tree-of-thoughts

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes shell commands to initialize its workspace by creating specific directories (.specs/research, .specs/reports) using mkdir -p to store intermediate reasoning files.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a complex workflow where user-supplied task descriptions and context are interpolated into prompts for multiple sub-agents (explorers, judges, and synthesizers).
  • Ingestion points: Placeholders such as {task_description} and {relevant_context} in SKILL.md are used to build prompts for sub-agents across all five phases.
  • Boundary markers: The instructions use XML-like tags (e.g., <task>, <selected_proposal>) to delimit external content, which provides a layer of separation but does not entirely eliminate injection risks.
  • Capability inventory: The skill has the capability to spawn sub-agents using different models (Opus, Sonnet) and perform file system write operations for research artifacts.
  • Sanitization: No explicit sanitization or filtering of the user-provided strings is documented before they are passed to the sub-agent prompts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 01:10 AM
Security Audit — agent-trust-hub — tree-of-thoughts