skills/ofoxai/skills/trellis-check/Gen Agent Trust Hub

trellis-check

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill executes a project-local Python script located at ./.trellis/scripts/get_context.py. This is a standard mechanism for project-specific automation and quality verification.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from local specification files (found in .trellis/spec/...) to guide its quality checks. While this represents an external data ingestion surface, it is consistent with the skill's purpose as a documentation-aware quality checker.
  • Ingestion points: Local filesystem paths under the .trellis/ directory.
  • Boundary markers: Absent; the agent reads the files directly into context.
  • Capability inventory: Execution of shell commands (git, grep, python3) and filesystem access.
  • Sanitization: None; the skill assumes the project specification files are trusted documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 08:46 AM