tailrocks-simplify-audit

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external code and metadata from pull requests, branches, and diffs. The skill architecture includes explicit boundary markers in references/runtime-trust.md to treat external content as untrusted data. It also includes capability inventory and sanitization instructions for command execution in Step 6 of SKILL.md, mandating the use of read-only filesystems and disabled networking to mitigate risks from processing potentially malicious third-party content.
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands to inspect tests and verify code removal candidates. While Step 6 of SKILL.md includes extensive safety measures such as environment isolation, secret scrubbing, and resource bounding, the ability to trigger command execution on external repository content represents a functional capability that warrants monitoring.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 03:12 PM
Security Audit — agent-trust-hub — tailrocks-simplify-audit