trellis-brainstorm

Pass

Audited by Gen Agent Trust Hub on Jun 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute a local repository script 'python3 ./.trellis/scripts/task.py' using a 'short goal' derived from user input. This creates an indirect command injection surface where a malicious user could provide a goal containing shell metacharacters to attempt execution of unauthorized commands on the local system.
  • [PROMPT_INJECTION]: The instructions employ strong imperative language such as 'CoreRule', 'Non-negotiable', and 'Mandatory' to define the agent's operational framework. While intended for workflow enforcement, this steering technique aims to override the agent's default decision-making process in favor of the skill's specific logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 21, 2026, 03:04 PM
Security Audit — agent-trust-hub — trellis-brainstorm