ponytail-debt
Pass
Audited by Gen Agent Trust Hub on Jul 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: Executes shell commands
grepandgit blameto scan the repository and identify code ownership. These are standard operations for development tools. - [PROMPT_INJECTION]: Presents a surface for indirect prompt injection as it ingests untrusted content from the codebase (comments starting with
ponytail:). - Ingestion points: Repository files via
grepinSKILL.md. - Boundary markers: Absent; the skill does not use specific delimiters to isolate the scanned code comments.
- Capability inventory: Shell execution (
grep,git blame) and file-write access (PONYTAIL-DEBT.md). - Sanitization: No sanitization or validation of the comment content is performed before the agent processes and reports it.
Audit Metadata