psi
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to read and execute custom development workflows and commands defined in project files such as
AGENTS.mdandREADME.md. An attacker who can influence the content of these files could potentially inject instructions to be executed by the agent. - Ingestion points: Documentation files (
AGENTS.md,README.md) read during the Plan, Spec, and Implement phases, as specified inSKILL.mdandreferences/implement-phase.md. - Boundary markers: There are no explicit instructions or delimiters defined to prevent the agent from following malicious instructions embedded within these documentation files.
- Capability inventory: The skill allows the agent to execute shell commands for testing and CI verification, modify project files, and write to the user's home directory (
~/.dot-agent/). - Sanitization: The skill does not provide mechanisms to sanitize or validate the content of the documentation files before processing them.
- [COMMAND_EXECUTION]: The
Implementphase protocol explicitly directs the agent to run CI checks, tests, and linting commands. While standard for development, this capability allows for the execution of arbitrary commands defined in the project's environment and configuration, which could be exploited through indirect injection.
Audit Metadata