tailrocks-remediate
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted repository files, reports, and tool outputs which establishes an attack surface for indirect prompt injection.
- Ingestion points:
references/runtime-trust.mdidentifies repository files, tool output, and web content as input sources. - Boundary markers: Present.
references/runtime-trust.mdcontains explicit instructions that embedded instructions cannot alter scope or authority. - Capability inventory:
SKILL.mdpermits file mutation via CAS and command execution under specific authority. - Sanitization: Present. Instructions include secret scrubbing and citation-only reporting for sensitive data.
- [COMMAND_EXECUTION]: The skill facilitates the execution of shell commands for remediation and regression testing. These actions are strictly gated by requirements for explicit execution authority, frozen dependencies, secret scrubbing, and repository state verification (CAS) before and after mutations as described in
SKILL.mdstep 4.
Audit Metadata