herdr-worktrunk
Warn
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection via project-controlled files. An attacker who can commit files to a repository can control the agent's behavior.
- Ingestion points: Reads and processes data from
AGENTS.md,.config/wt.toml,justfile,package.json, and various lockfiles within the target repository (SKILL.mdsection '前置检查' and '接入项目自动化'). - Boundary markers: While the instructions mention '审阅' (reviewing) configurations, there are no hard technical boundaries or 'ignore instructions' markers preventing the agent from following malicious directives embedded in these files.
- Capability inventory: The skill has the capability to write to the filesystem, execute shell commands, and interact with the Herdr agent management system across all scripts.
- Sanitization: No automated sanitization or schema validation of the ingested repository configuration is performed before it is used to construct shell commands.
- [COMMAND_EXECUTION]: The skill executes arbitrary project commands with automated approval flags, increasing the risk of unauthorized operations.
- Evidence: The skill explicitly uses the
--yesflag withwt(Worktrunk) commands to execute hooks defined in the repository's.config/wt.tomlfile without further user intervention (e.g.,wt -C "$repo" switch ... --yesandwt -C "$checkout" hook pre-start ... --yes). - Evidence: It executes various project-specific tools such as
just,npm,pnpm, anduvbased on the discovery of configuration files in the local environment. - [DYNAMIC_EXECUTION]: The skill dynamically loads logic from external sources at runtime, which could be subverted.
- Evidence: Section '前置检查' in
SKILL.mdinstructs the agent to '加载已安装的 herdr/SKILL.md;缺失时读 herdr --skill' (Load the installed herdr/SKILL.md; if missing, read herdr --skill), effectively performing a dynamic load of operational instructions. - [CREDENTIALS_UNSAFE]: The skill processes project configurations that may contain sensitive data, creating an exposure risk during reporting or execution.
- Evidence: The skill notes in '接入项目自动化' that
.config/wt.tomlmay contain private values. While it attempts to limit reporting to command names and statuses, the agent still reads and acts upon these sensitive configurations.
Audit Metadata