skills/taecontrol/skills/cleaner/Gen Agent Trust Hub

cleaner

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data (specs, code diffs, etc.) while maintaining capabilities to modify files and execute validation tools. This combination represents an attack surface for indirect prompt injection.
  • Ingestion points: Step 1 reads multiple external documents such as SPEC, SLICES, and candidate diffs.
  • Boundary markers: The process includes instructions to reject superseded inputs and strictly avoid reading artifacts or mutating resources outside the assigned workspace.
  • Capability inventory: The agent is authorized to repair code (Step 3), materialize candidates (Step 4), and execute project-profile gates (Step 5).
  • Sanitization: The instructions do not define specific methods for sanitizing or escaping content from external files before processing.
  • [NO_CODE]: The skill consists solely of instructions and metadata without any attached script files or binary executables.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 06:32 PM
Security Audit — agent-trust-hub — cleaner