freeze

Pass

Audited by Gen Agent Trust Hub on Mar 28, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill operates as a defensive mechanism to limit the agent's write and edit capabilities to a specific filesystem boundary, which is a security best practice for minimizing the impact of unintended modifications.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied path prefixes to establish its security boundaries, representing a standard injection surface. • Ingestion points: Untrusted input enters the skill through the 'allowed path prefix' argument. • Boundary markers: The skill does not define explicit delimiters for the path variable within its internal state file instructions. • Capability inventory: The skill utilizes 'Read', 'Write', 'Edit', and 'AskUserQuestion' tools to manage its state and enforce restrictions. • Sanitization: The instructions do not specify explicit validation or sanitization for the provided path prefix, relying on the underlying agent's path resolution safety.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 28, 2026, 12:11 PM
Security Audit — agent-trust-hub — freeze