tailrocks-agents-md

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill executes an external script (agents-md-topology.ts) located at a path computed relative to its installation directory. The implementation includes significant security controls to verify the script's integrity, such as checking for symlink components and ensuring the script is the installed version rather than a file within the target repository.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from the target repository, including AGENTS.md files, to determine rule placement and mutation actions.
  • Ingestion points: The skill binds repository text and existing instruction files as evidence in SKILL.md.
  • Boundary markers: The references/runtime-trust.md file defines a clear trust boundary, stating that repository content is untrusted and cannot override the agent's scope or authority.
  • Capability inventory: The skill possesses file-writing capabilities and the ability to execute the specific topology script.
  • Sanitization: The skill performs atomic writes via compare-and-swap and validates all paths before link creation, though it relies on model interpretation for the content of ingested files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 03:11 PM
Security Audit — agent-trust-hub — tailrocks-agents-md