tailrocks-improve-deep
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill audits software repositories, which involves ingesting untrusted code, scripts, and metadata (ingestion points: repository file paths and content referenced in SKILL.md). It mitigates risks by requiring all excerpts to be fenced and labeled as evidence, while explicitly instructing the agent that repository content grants no authority and must not alter governing rules (boundary markers: repository-audit-lanes.md, runtime-trust.md). The capability inventory includes executing limited analysis tools and generating a report (SKILL.md). Sanitization is enforced through adversarial re-reading, secret scrubbing, and mandatory refutation by an independent verifier (SKILL.md, runtime-trust.md).
- [COMMAND_EXECUTION]: The skill provides instructions for running target analysis commands on packages (SKILL.md). This execution is restricted to an enforceably read-only tree with frozen inputs, scrubbed secrets, and disabled network access to prevent unauthorized side effects or exfiltration.
Audit Metadata