rules-distill

Pass

Audited by Gen Agent Trust Hub on Mar 24, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local bash scripts scripts/scan-skills.sh and scripts/scan-rules.sh to inventory the system. These scripts use standard utilities like find, awk, and jq to extract metadata and headings.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests the full text of other skills and rule files. 1. Ingestion points: Skill and rule content read in scripts/scan-skills.sh and scripts/scan-rules.sh. 2. Boundary markers: Lacks robust delimiters or markers beyond simple headers. 3. Capability inventory: Ability to create or modify local rule files. 4. Sanitization: No explicit sanitization or filtering of external content is performed. This vulnerability is mitigated by a mandatory manual review process for all generated changes.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 24, 2026, 07:42 AM
Security Audit — agent-trust-hub — rules-distill