skills/paleo/alignfirst/alcatchupaad/Gen Agent Trust Hub

alcatchupaad

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses npx to execute the alignfirst CLI tool for fetching ticket history and retrieval of protocol guides.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external sources that could contain malicious instructions.
  • Ingestion points: External ticket history and the 'aad' protocol guide fetched via npx alignfirst (SKILL.md).
  • Boundary markers: None identified in the instructions to delimit or warn against instructions within the fetched content.
  • Capability inventory: The skill has the capability to execute shell commands via npx and read/write work files as per the retrieved guide.
  • Sanitization: No explicit sanitization or validation of the fetched history or guide content is mentioned.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 05:19 PM
Security Audit — agent-trust-hub — alcatchupaad