yes-md

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to process external data such as logs, configuration files, and network responses using powerful tools like bash and curl.
  • Ingestion points: External files, logs, and API responses (SKILL.md).
  • Boundary markers: No specific delimiters are specified for separating untrusted data from agent instructions.
  • Capability inventory: The skill requires access to bash, curl, and file system read/write operations (SKILL.md).
  • Sanitization: No instructions for filtering or sanitizing ingested data are provided.
  • [DYNAMIC_EXECUTION]: The skill promotes the generation and execution of shell commands and scripts to perform and verify engineering work.
  • Evidence: Instructions to provide and execute commands for testing and verification (SKILL.md).
  • Risk factor: Direct execution of AI-generated code represents a dynamic execution surface, which is a standard but relevant security consideration.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 11:44 PM
Security Audit — agent-trust-hub — yes-md