grilling-for-routine

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill acts as a prompt generator for automated tasks, processing user-supplied routine ideas and prompt configuration files which could contain malicious instructions. 1. Ingestion points: Processes user-defined routine ideas and external prompt.md files (SKILL.md). 2. Boundary markers: Explicitly requires human confirmation for critical actions, stating 'The human accepts. A Run never writes' and utilizing temporary folders for drafts. 3. Capability inventory: Executes shell commands through tools like dora, hermes, and npx (SKILL.md). 4. Sanitization: Employs a mandatory human-in-the-loop review process for all file operations and sensitive configuration updates.
  • [EXTERNAL_DOWNLOADS]: The skill documents the use of external sources for dependencies, including GitHub repositories (e.g., github.com/scalekit-inc/skillkit) and the npm registry via npx. These resources are associated with the tool's intended vendor ecosystem.
  • [COMMAND_EXECUTION]: Instructs the agent to perform various management and diagnostic commands such as 'dora harness models' and 'hermes config get'. It identifies security-sensitive configuration changes like enabling subagent auto-approval but correctly prompts the user to execute these commands manually rather than running them automatically.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:46 AM
Security Audit — agent-trust-hub — grilling-for-routine