spike
Pass
Audited by Gen Agent Trust Hub on Aug 7, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides a framework for performing temporary experiments and includes strong safety guidelines, such as instructing the agent to use 'credentials-free values' and mandating the deletion of all artifacts—including files, directories, and branches—once results are reported. \n- [COMMAND_EXECUTION]: The instruction set calls for the use of standard develo p ment commands to create scratch pad files, manage Git branches or worktree s, and modify the local '.git/info/exclude' file to prevent temporary files from being tracked by the repository. \n- [PROMPT_INJECTION]: The skill facilitates a workflow where the agent reads and tests external data such as API response s and library output s, which are then used to generate subsequent report s. The re is a lack of explicit sanitization or boundary marker s to prevent the agent from potentially following instruction s embedded within that external data. (Ingestion: API response s and tes t output s; Boundary Marker s: Absent; Capability Inventory: File writing, Git operation s, and code execution; Sanitization: Absent).
Audit Metadata