skills/ssheleg/super-ux/vision/Gen Agent Trust Hub

vision

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONPERSISTENCE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external project files to generate agent instructions and product documentation, creating a surface where malicious content in those files could influence agent behavior.
  • Ingestion points: Project documentation files (README.md, ARCHITECTURE.md, ROADMAP.md, CHANGELOG.md), configuration files (package.json, pyproject.toml, Cargo.toml), and project source code (entry points, services, routing table).
  • Boundary markers: None identified; the skill reads these files directly to extract product essence and principles.
  • Capability inventory: File creation and modification (docs/ux/vision.md, CLAUDE.md, AGENTS.md, GEMINI.md) and shell command execution (python3 docs/ux/lint.py).
  • Sanitization: None identified for the content extracted from project files before interpolation into the generated vision or rules.
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute a local Python script (python3 docs/ux/lint.py) for validation. While the script is intended to be a local tool seeded by the skill pack, it represents a command execution capability.
  • [PERSISTENCE]: The skill modifies the agent's environment by injecting a 'Vision alignment — hard rule' into host-specific instruction files (CLAUDE.md, AGENTS.md, or GEMINI.md). This modifies the agent's operational logic for all future sessions within the scope of the project.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 03:57 AM
Security Audit — agent-trust-hub — vision