to-spec
Pass
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute local Python scripts included in the package for data processing tasks. In
SKILL.md, the agent is directed to usefingerprint_spec.pyfor SHA256 hashing andenvelope_artifact.pyfor packaging content into length-delimited artifacts. These scripts do not perform network operations or access sensitive system credentials, serving solely for data integrity and formatting. - [PROMPT_INJECTION]: As the skill synthesizes conversation history into documentation, it possesses an indirect prompt injection surface. Ingestion points: Reads from the current conversation and named repository authorities. Boundary markers: The skill defines and uses a custom artifact envelope format (
---BEGIN CODEX CONVERSATION ARTIFACT---) to separate metadata from content and ensure traceability. Capability inventory: Includes local file reads, stdout writes, and execution of internal utility scripts via the Python interpreter. Sanitization: The provided Python scripts validate that all input is valid UTF-8 and strictly enforce a 10 MiB size limit to prevent resource exhaustion.
Audit Metadata