skills/simota/agent-skills/grove/Gen Agent Trust Hub

grove

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [SAFE]: The skill provides structural templates and auditing guidelines for code repositories. It uses standard shell commands for auditing and references well-known development tools. No malicious intent, obfuscation, or unsafe data handling was identified.
  • [COMMAND_EXECUTION]: The skill documentation includes examples of common shell commands (e.g., find, ls, git mv, wc) intended for local repository analysis. These are standard tools for the described use case of repository auditing and migration.
  • [INDIRECT_PROMPT_INJECTION]: The skill audits repository structures, creating an attack surface where malicious files in a processed project could attempt to influence the agent's behavior.
  • Ingestion points: The skill recipe audit and Step 1 of reference/llm-structure-audit.md ingest file names and directory trees.
  • Boundary markers: Absent; no explicit instructions are present to disregard instructions embedded in the audited files.
  • Capability inventory: The skill uses standard file system commands like find, ls, and git mv across its scripts.
  • Sanitization: Absent; no input sanitization or validation of the ingested file names is performed before processing.
  • [EXTERNAL_DOWNLOADS]: The skill references standard development tools and libraries from trusted organizations, such as GitHub's git-sizer. These references follow the project's guidance for using established community tooling.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 01:49 PM
Security Audit — agent-trust-hub — grove