om-setup-discovery-pipeline

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes content from repository files and tracker data which are considered untrusted ingestion points. It mitigates this risk by establishing a strict 'Untrusted content boundary' policy.\n
  • Ingestion points: Reads SDLC.md, AGENTS.md, and tracker-derived work data.\n
  • Boundary markers: Explicit instructions in references/agentic-setup.md mandate that the agent ignore embedded directives and report them as suspected injections.\n
  • Capability inventory: The skill is authorized to perform file writes to SDLC.md and configuration files, create directories, and execute git operations.\n
  • Sanitization: Configuration paths such as paths.specs are validated using a restricted alphanumeric regex to prevent path traversal attacks.\n- [COMMAND_EXECUTION]: The skill utilizes standard system utilities including git and jq to manage repository state and configuration files. These commands are localized to the documented setup workflow and intended repository maintenance.\n- [EXTERNAL_DOWNLOADS]: The skill identifies missing companion skills and provides the operator with npx command templates to facilitate manual installation from external package registries. These are provided as informational recommendations for the user.\n- [PROMPT_INJECTION]: Text patterns resembling prompt injection (e.g., 'ignore previous instructions') are included in the documentation purely as examples of malicious patterns that the agent is instructed to identify and disregard when processing repository content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 10:14 AM
Security Audit — agent-trust-hub — om-setup-discovery-pipeline