comet-runtime-diagnose

Pass

Audited by Gen Agent Trust Hub on Aug 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill instructions direct the agent to execute local runtime assets using the project's current working directory, specifically '执行真实打包 Runtime 路径' and '调用生成/打包后的 Router 或 Runtime'. While intended for debugging, this involves running code that the agent may have just read or modified.- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted local data that could contain malicious instructions designed to exploit the agent's command execution capabilities. 1. Ingestion points: The agent is instructed to read '../comet-github/references/maintainer-contract.md', along with source code, installed files, platform metadata, and lifecycle JSON/config files. 2. Boundary markers: Absent; no instructions are provided to delimit or ignore embedded commands in the processed files. 3. Capability inventory: The skill utilizes shell/command execution to run the Comet runtime and router. 4. Sanitization: Absent; no validation or escaping of ingested file content is mentioned.- [DATA_EXPOSURE]: The skill accesses files outside the immediate project root by reading '../comet-github/references/maintainer-contract.md'.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 14, 2026, 03:00 PM
Security Audit — agent-trust-hub — comet-runtime-diagnose