skills/plurigrid/asi/hof/Gen Agent Trust Hub

hof

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process CUE schemas, design files, and templates to generate code or execute workflows. This design creates a surface for indirect prompt injection where malicious instructions embedded in the processed data could influence the agent's behavior.
  • Ingestion points: Processes CUE files via 'hof gen' and 'hof flow', and receives user input via a VS Code chat interface.
  • Boundary markers: No specific boundary markers or 'ignore' instructions for processed content are defined in the documentation.
  • Capability inventory: Includes file system operations (fs_read, fs_write, fs_edit), shell command execution (exec, flow.#Exec), and network access via Model Context Protocol (MCP) integrations.
  • Sanitization: The skill documentation does not detail sanitization or validation protocols for external content before it is processed by the agent.
  • [COMMAND_EXECUTION]: The skill features a CUE-based flow engine and agent tools that explicitly support shell execution (flow.#Exec, exec). These are documented features intended for task automation and development workflows.
  • [EXTERNAL_DOWNLOADS]: The instructions specify downloading the 'hof' tool via 'go install' from a repository on GitHub (github.com/hofstadter-io/hof). It also references integrations with established services including GitHub Copilot and Tavily.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 02:44 PM