kernel-build
Pass
Audited by Gen Agent Trust Hub on Jul 11, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill identifies and executes shell commands defined within the target repository's configuration files, such as package.json or CI entrypoints. This behavior is essential to its primary function as a build-management tool.- [PROMPT_INJECTION]: The skill processes untrusted repository content (including documentation and build configurations) to guide its logic, which presents a surface for indirect prompt injection. However, the skill provides specific guardrails instructing the agent not to suppress errors or bypass quality standards without explicit user approval.
Audit Metadata