freeze
Pass
Audited by Gen Agent Trust Hub on Mar 28, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill operates as a defensive mechanism to limit the agent's write and edit capabilities to a specific filesystem boundary, which is a security best practice for minimizing the impact of unintended modifications.
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied path prefixes to establish its security boundaries, representing a standard injection surface. • Ingestion points: Untrusted input enters the skill through the 'allowed path prefix' argument. • Boundary markers: The skill does not define explicit delimiters for the path variable within its internal state file instructions. • Capability inventory: The skill utilizes 'Read', 'Write', 'Edit', and 'AskUserQuestion' tools to manage its state and enforce restrictions. • Sanitization: The instructions do not specify explicit validation or sanitization for the provided path prefix, relying on the underlying agent's path resolution safety.
Audit Metadata