skills/rca32/skills/local-work/Gen Agent Trust Hub

local-work

Pass

Audited by Gen Agent Trust Hub on Aug 13, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external, potentially untrusted "repository-authoritative spec" files and repository instructions to guide the implementation of code changes and the execution of verification tests.
  • Ingestion points: The agent is instructed to read a "repository-authoritative spec file" and "repository instructions" as the primary sources of truth for behavior changes in SKILL.md (Authority and selection section).
  • Boundary markers: The workflow utilizes a mandatory fingerprinting script (to-spec) to bind the work set to a specific file version, ensuring integrity against unauthorized modifications to the spec during the process, as described in the "Prepare the work set" section of SKILL.md.
  • Capability inventory: The skill possesses significant capabilities, including the authority to modify the codebase via the tdd tool, perform file system writes to generate work documents, and execute "focused and risk-appropriate surrounding verification" commands (SKILL.md, Execute one item section).
  • Sanitization: The instructions do not specify a mechanism for sanitizing or filtering the content of the authoritative spec to prevent it from containing malicious instructions that could influence the agent's implementation logic or test verification commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 13, 2026, 02:20 AM
Security Audit — agent-trust-hub — local-work