skills/opencue/colony/co-build/Gen Agent Trust Hub

co-build

Pass

Audited by Gen Agent Trust Hub on Jun 21, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The procedure explicitly instructs the agent to perform file edits and run tests. These capabilities are required for the skill's purpose but involve direct system interaction and code execution.
  • [PROMPT_INJECTION]: The skill processes task descriptions from CHANGE.md and specifications from SPEC.md, creating a surface for indirect prompt injection.
  • Ingestion points: Task definitions in CHANGE.md (§T) and documentation in SPEC.md (§V, §I, §T).
  • Boundary markers: None identified in the instructions; the agent is not directed to use specific delimiters or ignore embedded commands.
  • Capability inventory: File system modification and test execution commands (SKILL.md).
  • Sanitization: None described; the agent is expected to use the raw task text for planning and execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 21, 2026, 12:39 PM
Security Audit — agent-trust-hub — co-build