sweep

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a local shell script at .os/core/lib/sweep.sh to perform task scans. This is a functional command intended for repository management.
  • [PROMPT_INJECTION]: The skill processes frontmatter data from various initiatives and organizations, which creates a surface for indirect prompt injection. 1. Ingestion points: File frontmatter across the 'brain' and mounted nodes as described in SKILL.md. 2. Boundary markers: No explicit markers are defined to help the agent distinguish between file data and commands. 3. Capability inventory: Execution of a local shell script .os/core/lib/sweep.sh. 4. Sanitization: No sanitization methods are described for the frontmatter content being processed.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 08:57 PM
Security Audit — agent-trust-hub — sweep