tailrocks-remediate

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted repository files, reports, and tool outputs which establishes an attack surface for indirect prompt injection.
  • Ingestion points: references/runtime-trust.md identifies repository files, tool output, and web content as input sources.
  • Boundary markers: Present. references/runtime-trust.md contains explicit instructions that embedded instructions cannot alter scope or authority.
  • Capability inventory: SKILL.md permits file mutation via CAS and command execution under specific authority.
  • Sanitization: Present. Instructions include secret scrubbing and citation-only reporting for sensitive data.
  • [COMMAND_EXECUTION]: The skill facilitates the execution of shell commands for remediation and regression testing. These actions are strictly gated by requirements for explicit execution authority, frozen dependencies, secret scrubbing, and repository state verification (CAS) before and after mutations as described in SKILL.md step 4.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 03:12 PM
Security Audit — agent-trust-hub — tailrocks-remediate