skills/repowise-dev/modpack/five-whys/Gen Agent Trust Hub

five-whys

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructions direct the agent to ingest and analyze external data such as code, logs, or system state to identify root causes.
  • Ingestion points: The agent is encouraged to use Read, Grep, and Bash to investigate 'unknown' causes within the project environment.
  • Boundary markers: The skill does not define specific markers or instructions to isolate or ignore potentially malicious commands embedded in the data being investigated.
  • Capability inventory: The agent has access to Read, Grep, and Bash tools as explicitly mentioned in the investigation protocol.
  • Sanitization: No specific sanitization or filtering logic is provided to handle untrusted content before it is processed by the agent to form the reasoning chain.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 12:44 AM
Security Audit — agent-trust-hub — five-whys