skills/taecontrol/skills/deliver/Gen Agent Trust Hub

deliver

Warn

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructions require the agent to "run the full-project technical gates required by the accepted specification and executable project configuration." This allows for the execution of arbitrary shell commands based on the contents of external files provided at runtime.
  • [DYNAMIC_EXECUTION]: The workflow involves dispatching sub-agents (Implementer and Finisher) that "execute the applicable gates against the final state" of the code. Because the specific commands and their parameters are determined dynamically from the implementation specification and project metadata, this constitutes dynamic execution of logic derived from external input.
  • [INDIRECT_PROMPT_INJECTION]: The "Product Validator" role uses "native computer use or browser use tools" to interact with the software's user interface. Interacting with and processing data from a live application UI exposes the agent to instructions embedded in that UI content, which could be designed to override agent behavior.
  • Ingestion points: Implementation specifications, repository files, and live product UI content accessed via browser or computer use tools.
  • Boundary markers: The skill mentions respecting "sensitive policy" and "authority boundaries," and utilizes "fresh" agent contexts for each role dispatch to provide isolation.
  • Capability inventory: Shell command execution (technical gates), Git operations (status, history, commit), and full browser/computer control for UI interaction.
  • Sanitization: The instructions do not define explicit sanitization or filtering mechanisms for data ingested from the project files or the UI environment.
  • [EXTERNAL_DOWNLOADS]: The skill references an external CLI tool named "Manuvra" (manuvra version) as a preferred method for performing automated UI validation. The integrity and source of this tool are not verified within the skill's instructions.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 21, 2026, 07:22 PM
Security Audit — agent-trust-hub — deliver