simready-foundation-add-profile
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute local validation commands (
workspace validateorsimready-validate). These are project-specific tools intended to verify the integrity of the generated configuration files. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the repository, including existing feature JSON manifests and profile TOML files, to generate new profile definitions. While this presents an attack surface where malicious repository content could influence agent output, the risk is mitigated by the structured nature of the data and the skill's specific purpose.
- Ingestion points: Reads existing
*.tomlprofiles and*.jsonfeature manifests fromnv_core/tiers/. - Boundary markers: None explicitly defined in the instructions.
- Capability inventory: Performs file writes to the repository and executes local validation commands.
- Sanitization: No specific sanitization or filtering of the ingested repository content is described.
Audit Metadata