skills/shipshitdev/skills/critique/Gen Agent Trust Hub

critique

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill is instructed to run scripts defined in the target project's package.json file if they are configured for linting or design checks (Step 2, Assessment B). This behavior allows a malicious repository to execute arbitrary shell commands by embedding them within standard script fields that the agent is expected to run automatically during the critique process.- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the project being reviewed, which could be used to influence the agent's output or actions.
  • Ingestion points: SKILL.md (Step 1) specifies reading source files (HTML, CSS, JS/TS), .impeccable.md, and .github/copilot-instructions.md to gather brand and audience context.
  • Boundary markers: No specific delimiters or "ignore instructions" warnings are implemented when processing the content of these external files.
  • Capability inventory: The skill has the capability to execute commands via package.json scripts and manipulate browser session state (e.g., modifying document titles via browser automation).
  • Sanitization: No sanitization or validation of the ingested content is described before it is synthesized into the final report.- [DYNAMIC_EXECUTION]: The skill dynamically identifies and executes commands based on the contents of the project's local configuration files (package.json) rather than using a static, pre-defined set of safe tools or commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 05:10 AM
Security Audit — agent-trust-hub — critique