get-context

Pass

Audited by Gen Agent Trust Hub on Jul 15, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • Command Execution via Preflight Scripts: The skill instructions involve running a "preflight script" from a referenced skill file (user-context/SKILL.md) when shell access is available. This pattern is typically used for automated environment setup and context gathering within the local workspace.
  • Indirect Prompt Injection Surface: The skill is designed to ingest and process external grounding material such as Figma files, Storybook links, and codebase paths. This provides an entry point for untrusted data that could potentially influence agent behavior if the external sources contain embedded instructions.
  • Ingestion points: External project assets including Figma files, screenshots, codebase paths, and Storybook components.
  • Boundary markers: No explicit delimiters or boundary instructions are defined in this specific file to isolate untrusted content.
  • Capability inventory: The skill requests shell access to execute local setup and preflight scripts.
  • Sanitization: There are no specific sanitization or validation steps mentioned for the ingested external material.
  • Internal Workflow Constraints: The skill utilizes directives like "Critical Overrides" and "Hard boundary" to enforce specific design workflows. These are used to ensure the agent clarifies the product design target before initiating implementation tasks like creating files or starting servers.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 15, 2026, 02:40 AM
Security Audit — agent-trust-hub — get-context