herdr-worktrunk

Warn

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection via project-controlled files. An attacker who can commit files to a repository can control the agent's behavior.
  • Ingestion points: Reads and processes data from AGENTS.md, .config/wt.toml, justfile, package.json, and various lockfiles within the target repository (SKILL.md section '前置检查' and '接入项目自动化').
  • Boundary markers: While the instructions mention '审阅' (reviewing) configurations, there are no hard technical boundaries or 'ignore instructions' markers preventing the agent from following malicious directives embedded in these files.
  • Capability inventory: The skill has the capability to write to the filesystem, execute shell commands, and interact with the Herdr agent management system across all scripts.
  • Sanitization: No automated sanitization or schema validation of the ingested repository configuration is performed before it is used to construct shell commands.
  • [COMMAND_EXECUTION]: The skill executes arbitrary project commands with automated approval flags, increasing the risk of unauthorized operations.
  • Evidence: The skill explicitly uses the --yes flag with wt (Worktrunk) commands to execute hooks defined in the repository's .config/wt.toml file without further user intervention (e.g., wt -C "$repo" switch ... --yes and wt -C "$checkout" hook pre-start ... --yes).
  • Evidence: It executes various project-specific tools such as just, npm, pnpm, and uv based on the discovery of configuration files in the local environment.
  • [DYNAMIC_EXECUTION]: The skill dynamically loads logic from external sources at runtime, which could be subverted.
  • Evidence: Section '前置检查' in SKILL.md instructs the agent to '加载已安装的 herdr/SKILL.md;缺失时读 herdr --skill' (Load the installed herdr/SKILL.md; if missing, read herdr --skill), effectively performing a dynamic load of operational instructions.
  • [CREDENTIALS_UNSAFE]: The skill processes project configurations that may contain sensitive data, creating an exposure risk during reporting or execution.
  • Evidence: The skill notes in '接入项目自动化' that .config/wt.toml may contain private values. While it attempts to limit reporting to command names and statuses, the agent still reads and acts upon these sensitive configurations.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 12, 2026, 05:21 AM
Security Audit — agent-trust-hub — herdr-worktrunk