prath-mode
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references the
skillsNode.js package and theprathamdby/skillsrepository for managing dependencies. These are vendor-owned resources used to provide the underlying sub-skills referenced in the routing map. - [COMMAND_EXECUTION]: Instructions include a command (
npx skills@latest add prathamdby/skills) to be reported to the user if required components are missing. This is a standard installation procedure for the skill's ecosystem. - [INDIRECT_PROMPT_INJECTION]: The skill ingests content from local
SKILL.mdfiles and implementation artifacts such as diffs and test results. - Ingestion points: Relative skill file paths (e.g.,
../commit/SKILL.md) and implementation ledgers. - Boundary markers: Absent; the skill relies on the structural validity of the local files it references.
- Capability inventory: Execution of sub-skills, terminal state verification, and recording diffs.
- Sanitization: None observed for the ingested diffs or sub-skill procedures.
Audit Metadata