pre-flight-check

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a local shell script scripts/pre-flight.sh which uses standard utilities like grep, find, awk, and wc to analyze project-local files.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from local markdown files that may contain externally-sourced content.
  • Ingestion points: Processes content from .learnings/LEARNINGS.md, .learnings/ERRORS.md, .learnings/FEATURE_REQUESTS.md, .learnings/HEALS.md, .evals/EVAL_INDEX.md, and the .context-surfing/ directory.
  • Boundary markers: The automatic hook output uses <pre-flight-check> XML-style tags to delimit findings, though the manual scan output relies on standard markdown headers.
  • Capability inventory: The script performs read-only file system operations; however, the skill instructs the agent to act on the discovered patterns, which involves using other tools with broader capabilities (e.g., learning-aggregator).
  • Sanitization: No explicit sanitization or filtering of instructions is performed on the data read from files before it is presented to the agent's context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 08:41 AM
Security Audit — agent-trust-hub — pre-flight-check