dev-rfc
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes a local TypeScript/JavaScript server using
bun runto provide an interactive review interface. - The script
scripts/generate_review.ts(or the Python equivalentscripts/generate_review.py) is executed to manage the review lifecycle. - The Python script uses
subprocess.runto call system tools (lsof,fuser) for port cleanup. - [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface where malicious instructions could be embedded in the RFC markdown or the feedback provided via the web UI.
- Ingestion points: The agent reads feedback from the workspace file
.rfc-review/feedback.jsonas specified inSKILL.md. - Boundary markers: The feedback is ingested as structured JSON, but there are no specific delimiters or "ignore" instructions for the content within the JSON fields.
- Capability inventory: The skill can execute local commands (
bun run), perform local HTTP requests (curl), and read/write files. - Sanitization: The web UI uses the
markedlibrary for rendering markdown, but the agent reads the raw JSON feedback without explicit sanitization of the text content.
Audit Metadata