@1892/disk-manager

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's operation involves scanning the workspace and presenting file and directory names to the agent to facilitate cleanup decisions. This process is vulnerable to indirect prompt injection as malicious filenames could be crafted to act as instructions to the LLM.
  • Ingestion points: scripts/scan_workspace.py and scripts/safe_cleanup.py read and report directory and file names from the /data/workspace directory.
  • Boundary markers: The skill lacks explicit boundary markers or instructions to the agent to treat the reported filenames as literal data, increasing the risk that the agent might follow instructions embedded in a filename.
  • Capability inventory: The skill includes scripts for file and directory deletion (scripts/safe_cleanup.py) and project archiving (scripts/archive_project.py), providing a high-impact target for successful injections.
  • Sanitization: Path names and filenames are not sanitized or escaped before being displayed to the agent in the report generated by the scanning scripts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 06:49 PM
Security Audit — agent-trust-hub — @1892/disk-manager